npm Alert
2375Warning Date
Severity Level
Warning Number
Target Sector
21 April, 2022
● Medium
2022-4696
All
npm has released security updates to address a vulnerability in the following product:
- convict
- < 6.2.2
Attacker could exploit this vulnerability by executing arbitrary code.
The CERT team encourages users to review npm security advisory and apply the necessary update: