Skip to content

[CVE/Security] CVE-2021-44906, minimist, in npm v6 #4799

Closed
@mrbusche

Description

@mrbusche

A critically rated CVE, CVE-2021-44906, is present in npm v6, minimist version 1.2.5 is vulnerable and the issue is fixed in 1.2.6.

I'm happy to submit a new package-lock.json after running npm audit fix. Doesn't look like any other files need updated based on the history of package-lock.json on v6 branch.

Metadata

Metadata

Labels

Release 6.xwork is associated with a specific npm 6 releaseSecuritysecurity related

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions