Skip to content

Old version of debug dependency introduces CVE-2017-16137 vulnerability #2146

@amin-kchaou

Description

@amin-kchaou

Issue

nodemon uses debug@^3.2.7 which contains the CVE-2017-16137 vulnerability.
The earliest fix for this vulnerability is in [email protected]. It would be appreciated it you could update nodemon's debug to that or higher.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions