You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We maintain a fork of Prebid.js that is being flagged by Dependabot as containing a critical security vulnerability, introduced by babel-traverse (ID: CVE-2023-45133)
In Prebid.js, it looks to be coming from babel-register via:
patmmccann
changed the title
Critical security vulnerability via babel-traverse 6.26.0
Minor security vulnerability via babel-traverse 6.26.0
Jul 22, 2024
Type of issue
Security vulnerability
Description
We maintain a fork of Prebid.js that is being flagged by Dependabot as containing a critical security vulnerability, introduced by
babel-traverse
(ID: CVE-2023-45133)In Prebid.js, it looks to be coming from
babel-register
via:Relevant line in package.json
babel-register
is used to add Babel support to the end-to-end testing task.It is reasonable to assume that the end-to-end testing tasks (
gulp e2e-test
) are currently insecure. Do you agree, and if so, would it be possible to upgrade[email protected]
to@babel/[email protected]
or higher?Platform details
This affects at least versions v8.52.0 and v9 (latest) of Prebid.js
The text was updated successfully, but these errors were encountered: