-
|
Rollup Plugin Name: @rollup/plugin-terser # npm audit report
serialize-javascript <=7.0.2
Severity: high
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() - https://github.com/advisories/GHSA-5c6j-r48x-rmvq
fix available via `npm audit fix --force`
Will install @rollup/plugin-terser@0.1.0, which is a breaking change
node_modules/serialize-javascript
@rollup/plugin-terser >=0.2.0
Depends on vulnerable versions of serialize-javascript
node_modules/@rollup/plugin-terserAdditional InformationHappens when doing |
Beta Was this translation helpful? Give feedback.
Answered by
trimble
Mar 2, 2026
Replies: 2 comments 1 reply
-
|
See #1968 |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
Khoeckman
-
|
But this will be solved or we need to do a workaround? |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
See #1968