Skip to content

prismjs: vulnerability: GHSA-x7hr-w5r2-h6wg #603

@manstis

Description

@manstis

JFYI @patternfly/chatbot version 6.3.0-prerelease.25 fails npm audit.

# npm audit report

prismjs  <1.30.0
Severity: moderate
PrismJS DOM Clobbering vulnerability - https://github.com/advisories/GHSA-x7hr-w5r2-h6wg
No fix available
node_modules/refractor/node_modules/prismjs
  refractor  <=4.6.0
  Depends on vulnerable versions of prismjs
  node_modules/refractor
    react-syntax-highlighter  >=6.0.0
    Depends on vulnerable versions of refractor
    node_modules/react-syntax-highlighter
      @patternfly/chatbot  *
      Depends on vulnerable versions of react-syntax-highlighter
      node_modules/@patternfly/chatbot

No fix is currently available in the underlying library prismjs.

Metadata

Metadata

Assignees

Labels

PF6Applies to only the PF6 version

Type

Projects

Status

Done

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions