-
Notifications
You must be signed in to change notification settings - Fork 2.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Withdrawn: Arbitrary Code Execution in static-eval #2342
Comments
Version of pdfmake is? |
@liborm85 |
Vulnerability is only in version 0.1.x. |
Can we please fix this? NPM will try to fix it by alternatively installing 0.1.72 or 0.2.2. depending on what you have installed. |
How I solve it in pdfmake if vulnerable pdfkit is dependency in svg-to-pdfkit library and this pdfkit is not used by pdfmake or svg-to-pdfkit? |
The maintainers need to escalate this to svg-to-pdfkit as one of their dependents. If a package is installed but not used it should be removed by the dependencies maintainers. |
You can create issue here. |
Opened |
svg-to-pdfkit is in version pdfmake 0.2.3 build-in (without pdfkit dependency) ce50aeb. |
pdfmake module having vulnerabilities with following error
Withdrawn: Arbitrary Code Execution in static-eval
Team, can you please provide the solution for this?
The text was updated successfully, but these errors were encountered: