baseline-browser-mapping is vulnerable to Denial of Service (DoS)
66
Medium Risk
The getCompatibleVersions() and getAllVersions() functions in baseline-browser-mapping call process.exit() when they receive invalid or conflicting configuration options, such as supplying both targetYear and widelyAvailableOnDate, or setting includeKaiOS: true with includeDownstreamBrowsers: false. An application that forwards user-controlled values into these options can be forced to terminate its entire host process. The fix removes the process.exit() calls and throws a catchable Error instead.
You are affected if you are using a version that falls within the vulnerable range and your application passes user-controlled values into the getCompatibleVersions() or getAllVersions() configuration options without validating them first.
baseline-browser-mapping is vulnerable to Denial of Service (DoS) in versions 2.0.0 - 2.10.44.
Upgrade the baseline-browser-mapping library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant