Intel

AIKIDO-2024-10551

vant is vulnerable to Malicious Code

Malicious Code Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

100

Critical Risk

This Affects:

JSvant
2.13.3 - 2.13.5
Fixed in 2.13.6
3.6.13 - 3.6.15
Fixed in 3.6.16
4.9.11 - 4.9.14
Fixed in 4.9.15

TL;DR

Affected versions of this package were published using a compromised npm token and contain multiple security vulnerabilities. Users are strongly advised to avoid these versions and update to a secure release immediately.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

vant is vulnerable to Malicious Code in versions 2.13.3 - 2.13.5, 3.6.13 - 3.6.15 and 4.9.11 - 4.9.14.

How to fix this

Upgrade the vant library to a patch version.