@slidev/parser is vulnerable to Improper Input Validation
81
High Risk
Affected versions of slidev dynamically load theme and plugin packages from user-controlled slide frontmatter or CLI arguments without sufficient validation. An attacker able to modify presentation content can cause the application to load a malicious npm package, potentially resulting in arbitrary code execution and compromise of the developer’s environment.
You are affected if you are using a version that falls within the vulnerable range.
@slidev/parser is vulnerable to Improper Input Validation in versions 0.48.0 - 52.15.1.
Upgrade the slidev library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant