In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade devalue to version 5.9.3 or higher.
devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.
Affected versions of this package are vulnerable to Uncaught Exception via unhandled Promise rejections in stringifyAsync within src/stringify.js. When a Promise passed to stringifyAsync rejects before it is awaited in the sequential traversal loop, the rejection goes unhandled, causing an UnhandledPromiseRejection event that crashes the Node.js process.