You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Great work with this library! An issue I've had while using beeminderjs is that GitHub flags curlrequest as a security issue.
CVE-2020-7646 [high severity]
Vulnerable versions: <= 1.0.1
Patched version: No fix
curlrequest through 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands by using a semicolon char in any of the options values.
Is there a way for curlrequest to be replaced as a dependency, as there seems to be no dedicated owner of curlrequest and it hasn't been updated in years?
Thanks!
The text was updated successfully, but these errors were encountered:
Hi there,
Great work with this library! An issue I've had while using
beeminderjs
is that GitHub flagscurlrequest
as a security issue.Is there a way for
curlrequest
to be replaced as a dependency, as there seems to be no dedicated owner ofcurlrequest
and it hasn't been updated in years?Thanks!
The text was updated successfully, but these errors were encountered: