-
Notifications
You must be signed in to change notification settings - Fork 168
Open
Description
The package.json mention [email protected] which has several vulnerability, like GHSA-cpj6-fhp6-mr6j
But, nothing to worry about, as npm installed 7.6.2 thanks to ^, this version is good. But, hey!, its better to fix vulnerability as its mcp, anyway going to be run on users machine and can execute arbitrary code code (one of few drawbacks of mcp). I know this pakcage is not used in mcp code (or is?). But anyways...
Btw, i used https://github.com/safedep/vet to scan.
vishalsingh2972
Metadata
Metadata
Assignees
Labels
No labels
