@npmcli/arborist
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @npmcli/arboristpage 1 of 1
- CVE-2021-39134HIGHCVSS 8.2EG 8.2✓ Fixed in 2.8.22021-08-31
`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of pac…
- CVE-2021-39135HIGHCVSS 8.2EG 8.2✓ Fixed in 2.8.22021-08-31
`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of packa…
Check whether @npmcli/arborist is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @npmcli/arborist CVEs against the assets you own.
Start Free Scan →