Create-react-app: yargs-parser are vulnerable to prototype pollution in version 3.4.1

Created on 7 May 2020  路  5Comments  路  Source: facebook/create-react-app

Describe the bug

yargs-parser are vulnerable to prototype pollution in version 3.4.1

Expected behavior

should fix the security issue.

Actual behavior

yargs-parser are vulnerable to prototype pollution in version 3.4.1.

bug report needs triage

Most helpful comment

@ianschmitz I believe this issue is referring to react-scripts version 3.4.1 not yargs-parser.

-- [email protected]
+-- [email protected]
| -- [email protected]
| -- -- [email protected]
| -- -- -- [email protected]
-- [email protected]
-- -- [email protected]
-- -- -- [email protected]

All 5 comments

[email protected] doesn't exist.

@ianschmitz I believe this issue is referring to react-scripts version 3.4.1 not yargs-parser.

-- [email protected]
+-- [email protected]
| -- [email protected]
| -- -- [email protected]
| -- -- -- [email protected]
-- [email protected]
-- -- [email protected]
-- -- -- [email protected]

Why was this issue closed if the issue has not been fixed? react-scripts 3.4.1 is still vulnerable and will cause an npm audit to return non-zero:

Low Prototype Pollution 

Package yargs-parser 

Patched in >=13.1.2 <14.0.0 || >=15.0.1 <16.0.0 || >=18.1.2 

Dependency of react-scripts [dev] 

Path react-scripts > webpack-dev-server > yargs > yargs-parser 

More info https://npmjs.com/advisories/1500 

this has been resolved on master but not yet released: https://github.com/facebook/create-react-app/pull/8975

Any sense of when that release will be?

Was this page helpful?
0 / 5 - 0 ratings

Related issues

dualcnhq picture dualcnhq  路  3Comments

fson picture fson  路  3Comments

wereHamster picture wereHamster  路  3Comments

oltsa picture oltsa  路  3Comments

jnachtigall picture jnachtigall  路  3Comments