QID 981930
QID 981930: Nodejs (npm) Security Update for spritesheet-js (GHSA-333x-qr3v-g4xx)
This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-333x-qr3v-g4xx for updates pertaining to this vulnerability.
Vendor References
- GHSA-333x-qr3v-g4xx -
github.com/advisories/GHSA-333x-qr3v-g4xx
CVEs related to QID 981930
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-333x-qr3v-g4xx | spritesheet-js |
|