Storybook-readme: ReDoS vulnerability in `marked` package.

Created on 31 Jul 2019  路  4Comments  路  Source: tuchk4/storybook-readme

Looks like there's a Regular Expression Denial of Service (ReDoS) vulnerability in marked package version 0.6.0 according to the advisory here: https://www.npmjs.com/advisories/1076

Upgrading the package should fix it. I can put up a PR to fix that :)

Most helpful comment

Still an issue in 5.0.6

All 4 comments

Does it usually take long to publish these to npm? I just tried doing npm audit fix and it still says this:

 1 vulnerability required manual review and could not be updated

Still an issue in 5.0.6

For anyone following, new open issue @ #204

Was this page helpful?
0 / 5 - 0 ratings

Related issues

smrq picture smrq  路  9Comments

LukyVj picture LukyVj  路  5Comments

robcaldecottvelo picture robcaldecottvelo  路  5Comments

beyondghx picture beyondghx  路  6Comments

jayknott picture jayknott  路  6Comments