create-sitecore-jss is vulnerable to Use of Unmaintained Third-Party Components
10
Low Risk
Affected versions of this package used the unmaintained graphql-let library for GraphQL code generation, potentially exposing applications to several vulnerabilities as it could allow attackers to exploit known security flaws in the deprecated dependency due to the absence of patches.
You are affected if you are using a version that falls within the vulnerable range.
create-sitecore-jss is vulnerable to Use of Unmaintained Third-Party Components in versions 22.0.0 - 22.6.0.
Upgrade the create-sitecore-jss library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant