[GH-ISSUE #801] NPM Audit found vulnerabilities. #400

Closed
opened 2026-03-02 12:41:55 +03:00 by kerem · 1 comment
Owner

Originally created by @github-actions[bot] on GitHub (Mar 1, 2022).
Original GitHub issue: https://github.com/KelvinTegelaar/CIPP/issues/801

# npm audit report

prismjs  1.14.0 - 1.26.0
Severity: high
Cross-site Scripting in Prism - https://github.com/advisories/GHSA-3949-f494-cm99
fix available via `npm audit fix`
node_modules/prismjs
node_modules/refractor/node_modules/prismjs
  refractor  2.4.0 - 3.5.0 || 4.0.0 - 4.4.0
  Depends on vulnerable versions of prismjs
  node_modules/refractor

2 high severity vulnerabilities

To address all issues, run:
  npm audit fix

Originally created by @github-actions[bot] on GitHub (Mar 1, 2022). Original GitHub issue: https://github.com/KelvinTegelaar/CIPP/issues/801 ``` # npm audit report prismjs 1.14.0 - 1.26.0 Severity: high Cross-site Scripting in Prism - https://github.com/advisories/GHSA-3949-f494-cm99 fix available via `npm audit fix` node_modules/prismjs node_modules/refractor/node_modules/prismjs refractor 2.4.0 - 3.5.0 || 4.0.0 - 4.4.0 Depends on vulnerable versions of prismjs node_modules/refractor 2 high severity vulnerabilities To address all issues, run: npm audit fix ```
kerem closed this issue 2026-03-02 12:41:56 +03:00
Author
Owner

@KelvinTegelaar commented on GitHub (Mar 1, 2022):

I KNOW BOT WE DISCUSSED THIS. See https://github.com/KelvinTegelaar/CIPP/issues/798

<!-- gh-comment-id:1055450519 --> @KelvinTegelaar commented on GitHub (Mar 1, 2022): I KNOW BOT WE DISCUSSED THIS. See https://github.com/KelvinTegelaar/CIPP/issues/798
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/CIPP#400
No description provided.