npm Alert
2873Warning Date
Severity Level
Warning Number
Target Sector
2 October, 2022
● Critical
2022-5299
All
npm has released security update to address several vulnerabilities in the following products:
- d3-color < 3.1.0
- matrix-js-sdk < 19.7.0
- isolated-vm <= 4.3.6
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Spoofing attacks
- Execute arbitrary code
The CERT team encourages users to review npm security advisory and apply the necessary updates: