CriticalUpdate @tauri-apps/plugin-shell to fix a critical vulnerability(GHSA-c9pr)
Fix: 2.2.15.6/10
Update @tauri-apps/plugin-shell to fix a critical vulnerability(GHSA-c9pr)
Fix: 2.2.15.6/10Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell` @tauri-apps/plugin-shell is declared as "^2.3.5" and used as a production npm dependency of this repo. Severity: critical. Reported via GHSA-c9pr-q8gx-3mgp (GHSA).
Upgrade @tauri-apps/plugin-shell to 2.2.1 or later — low effort (minor version bump).
Claimed by @SpIob
▸Why this score?
Formula
0.60 × impact (9.0) + 0.40 × ecosystem value (0.5) = 5.6
Impact inputs
- CVSS: unknown
- Severity: critical
- Dependency type: production
- Advisory age: 519d
Ecosystem value inputs
- Repo stars: 1
- Open issues: 0
- Downstream dependents: not tracked yet
Effort inputs
- Semver bump: minor
- Migration guide: not tracked yet
Why low confidence
- · No CVSS score was available for this advisory; the impact score falls back to a severity-based estimate.
- · The number of packages depending on this repo's published package couldn't be checked, so ecosystem value is based on stars and issue activity only.
- · Changelog and migration-guide data wasn't available for this dependency's own upstream repository, so the effort estimate is based on the semver version bump alone.
Source
GHSA advisory GHSA-c9pr-q8gx-3mgp for @tauri-apps/plugin-shell