statsig-node is vulnerable to Insertion of Sensitive Information into Log File
25
Low Risk
Affected versions of this package may expose sensitive information, such as the SDK key, in the log files.
You are affected if you are using a vulnerable version of the package.
statsig-node is vulnerable to Insertion of Sensitive Information into Log File in versions 5.11.0 - 5.23.0.
Upgrade statsig-node to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant