Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in scss-tokenizer via sass-graph #1223

Closed
StephenTG opened this issue Jul 29, 2024 · 6 comments
Closed

Vulnerability in scss-tokenizer via sass-graph #1223

StephenTG opened this issue Jul 29, 2024 · 6 comments

Comments

@StephenTG
Copy link

There's a High severity vulnerability in scss-tokenizer (see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25758), which is included in this project via sass-graph.

@evenstensberg
Copy link
Member

@StephenTG
Copy link
Author

Looks like there's been a PR for almost 2 years for this: sasstools/scss-tokenizer#50

@evenstensberg
Copy link
Member

Last commit was 2years ago, so I don't think we will be able to fix this.

@StephenTG
Copy link
Author

sass-graph has a similar lack of recent updates, is there an alternative for that which could be used?

@evenstensberg
Copy link
Member

I've contacted the maintainer of scss-tokenizer, so will await what he answers.

@alexander-akait
Copy link
Member

Sorry, we can't fix it here, also node-sass is deprecated, please migrate on sass (dart) or sass-embedded

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants