Skip to content

Security concern – Crypto-browserify dependency on vulnerable elliptic package #251

@vkb-stack

Description

@vkb-stack

Hi Team,

I’d like to report a security concern regarding crypto-browserify. The package currently depends on elliptic, which has a known critical vulnerability in its elliptic curve cryptography implementation.

Affected dependency: elliptic

Package: elliptic

Severity: Critical

Impact: Potential compromise of cryptographic strength

Details:GHSA-6p4c-r453-8743: PuTTY

Could you please review this dependency and update it to a secure version or recommend a mitigation path?

Thank you for maintaining this project and your support in addressing this issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions