Skip to content

Security: jsonwebtoken dependency uses vulnerable jws@3.2.2 #1165

@MAlkabbani

Description

@MAlkabbani

Summary

The twilio package depends on jsonwebtoken@9.0.2 which in turn uses jws@3.2.2, which has a HIGH severity vulnerability (GHSA-869p-cjfg-cm3x) regarding improper HMAC signature verification.

Vulnerability Details

  • Package: jws
    • Vulnerable versions: <3.2.3
      • Patched versions: >=3.2.3

Request

Please update jsonwebtoken to a version that uses jws@3.2.3 or later, or update the dependency chain to resolve this vulnerability.

Current Path

`twilio@5.11.1

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions