QID 982082
QID 982082: Nodejs (npm) Security Update for @prisma/sdk (GHSA-pxcc-hj8w-fmm7)
Security update has been released for @prisma/sdk to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
As of today, we are not aware of any Prisma users or external consumers of the `@prisma/sdk` package who are affected by this security vulnerability.
This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input.
It only affects the `getPackedPackage` function and this function is not advertised and only used for tests & building our CLI, no malicious code was found after checking our codebase.
Solution
Fixed in
- @prisma/[email protected] (latest channel)
- @prisma/[email protected] (dev channel)
Pull Request closing this vulnerability [https://github.com/prisma/prisma/pull/6245](https://github.com/prisma/prisma/pull/6245)
- @prisma/[email protected] (latest channel)
- @prisma/[email protected] (dev channel)
Pull Request closing this vulnerability [https://github.com/prisma/prisma/pull/6245](https://github.com/prisma/prisma/pull/6245)
Vendor References
- GHSA-pxcc-hj8w-fmm7 -
github.com/advisories/GHSA-pxcc-hj8w-fmm7
CVEs related to QID 982082
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pxcc-hj8w-fmm7 | @prisma/sdk |
|