steal has critical vulnerabilities — do not use
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2022-37262 | steal vulnerable to Regular Expression Denial of Service via source and sourceWithComments | — |
| high | CVE-2022-37260 | steal vulnerable to Regular Expression Denial of Service via input variable | — |
| critical | CVE-2022-37264 | steal vulnerable to Prototype Pollution via optionName variable | — |
| critical | CVE-2022-37257 | steal vulnerable to Prototype Pollution via requestedVersion variable | — |
| critical | CVE-2022-37258 | steal vulnerable to Prototype Pollution | — |
| high | CVE-2022-37259 | steal Inefficient Regular Expression Complexity vulnerability via string variable | — |
| critical | CVE-2022-37266 | steal vulnerable to Prototype Pollution via key variable in babel.js | — |
| critical | CVE-2022-37265 | steal vulnerable to Prototype Pollution via alias variable | — |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/stealFirst published · 2013-06-26T16:32:23.980Z
Last updated · 2022-06-09T01:33:50.137Z