Skip to content

react-dev-utils: Prototype Pollution in Immer  #11443

Closed
@SalGnt-mxm

Description

@SalGnt-mxm

Describe the bug

The react-dev-utils package uses a vulnerable version (v8.0.4) of Immer.

The fix, commit fa671e5, is part of the v9.0.6 release.
The react-dev-utils package should use this specific version of Immer.

GitHub CVE

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions