Intel

AIKIDO-2025-10383

create-sitecore-jss is vulnerable to Use of Unmaintained Third-Party Components

Use of Unmaintained Third-Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 18, 2025

10

Low Risk

This Affects:

JScreate-sitecore-jss
22.0.0 - 22.6.0
Fixed in 22.7.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package used the unmaintained graphql-let library for GraphQL code generation, potentially exposing applications to several vulnerabilities as it could allow attackers to exploit known security flaws in the deprecated dependency due to the absence of patches.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

create-sitecore-jss is vulnerable to Use of Unmaintained Third-Party Components in versions 22.0.0 - 22.6.0.

How to fix this

Upgrade the create-sitecore-jss library to the patch version.