@vue/cli@3.7.0 vulnerabilities
Command line interface for rapid Vue.js development
-
latest version
5.0.8
-
latest non vulnerable version
-
first published
7 years ago
-
latest version published
2 years ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the @vue/cli package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
@vue/cli is a Command line interface for rapid Vue.js development Affected versions of this package are vulnerable to Remote Code Execution (RCE) on the user’s machine via Cross-Site WebSocket Hijacking.
Note: This vulnerability is exploitable only if the user explicitly exposes their Vue CLI UI server to the public network via the command How to fix Remote Code Execution (RCE)? Upgrade |
<4.5.14
>=5.0.0-alpha.0 <5.0.0-beta.6
|