styled-components@5.3.5 vulnerabilities

  • latest version

    6.1.18

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    16 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the styled-components package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Undesired Behavior

    Affected versions of this package are vulnerable to Undesired Behavior via the postinstall.js file which looks for users using a ru time-zone to show a political protest message using the console.warn() function. Also, the absence of this file in the 5.3.4 version causes a crash when the package is installed.

    How to fix Undesired Behavior?

    Upgrade styled-components to version 5.3.7 or higher.

    >=5.3.5 <5.3.7