CriticalnpmUpdate @tauri-apps/plugin-shell to fix a critical vulnerability
Low effort SpIob/FlowState ⚠ low confidence
Claimed · @SpIob5.6/10
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell` Affects @tauri-apps/plugin-shell (declared as "^2.3.5"), used as a production dependency of this repo. Severity: critical. Source: GHSA-c9pr-q8gx-3mgp (GHSA).
Upgrade @tauri-apps/plugin-shell to 2.2.1 or later (minor version bump).
Claimed by @SpIob
▸Why this score?
Formula
0.60 × impact (9.0) + 0.40 × ecosystem value (0.5) = 5.6
Impact inputs
- CVSS: unknown
- Severity: critical
- Dependency type: production
- Advisory age: 475d
Ecosystem value inputs
- Repo stars: 1
- Open issues: 0
- Downstream dependents: not tracked yet
Effort inputs
- Semver bump: minor
- Migration guide: not tracked yet
Why low confidence
- · No lock file was parsed for this dependency, so the currently-installed version is estimated from its declared range rather than confirmed.
- · No CVSS score was available for this advisory; the impact score falls back to a severity-based estimate.
- · The number of packages that depend on this one isn't tracked yet, so ecosystem value is based on stars and issue activity only.
- · Changelog and migration-guide data isn't ingested yet, so the effort estimate is based on the semver version bump alone.
Source
GHSA advisory GHSA-c9pr-q8gx-3mgp for @tauri-apps/plugin-shell