open-cli has a prototype pollution vulnerability in it's sub-dependency yargs-parser.
Vulnerability details:
Current dependency chain:
open-cli@5.0.0 -> meow@5.0.0 -> yargs-parser@10.1.0
Fix:
- Update
package.json to use fixed version of meow (version without vuln currently not available).
open-clihas a prototype pollution vulnerability in it's sub-dependencyyargs-parser.Vulnerability details:
yargs-parserfix commit: yargs/yargs-parser@63810caCurrent dependency chain:
open-cli@5.0.0->meow@5.0.0->yargs-parser@10.1.0Fix:
package.jsonto use fixed version ofmeow(version without vuln currently not available).