@parcel/install-package

@parcel/install-package

Releases2
Frequency18 minutes
Last Release
Blazing fast, zero configuration web application bundler

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
all versions9.8 CRITICAL7.5 HIGH

umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.

<= 0.4.09.8 CRITICAL7.5 HIGH

install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.