@slidev/parser is vulnerable to Improper Input Validation
81
High Risk
Affected versions of slidev dynamically load theme and plugin packages from user-controlled slide frontmatter or CLI arguments without sufficient validation. An attacker able to modify presentation content can cause the application to load a malicious npm package, potentially resulting in arbitrary code execution and compromise of the developer’s environment.
You are affected if you are using a version that falls within the vulnerable range.
@slidev/parser is vulnerable to Improper Input Validation in versions 0.48.0 - 52.15.1.
Upgrade the slidev library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant