eslint@6.0.0 vulnerabilities

An AST-based pattern checker for JavaScript.

  • latest version

    9.39.2

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the eslint package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Uncontrolled Recursion

    eslint is a pluggable linting utility for JavaScript and JSX

    Affected versions of this package are vulnerable to Uncontrolled Recursion in the isSerializable function when handling objects with circular references during the serialization process. An attacker can cause the application to crash or become unresponsive by supplying specially crafted input that triggers infinite recursion.

    How to fix Uncontrolled Recursion?

    Upgrade eslint to version 9.26.0 or higher.

    <9.26.0