cvss9.8
how bad it is if exploited, out of 10
epss2.8%
chance of exploitation in the next 30 days
xyz score4.6
CyberXYZ composite, out of 10
fig. 01 — GHSA-29gp-92wp-94q8, the advisory selected below
// advisories
GHSA-29gp-92wp-94q8
HIGHCVE-2018-6342react-dev-utils on Windows is vulnerable to remote code execution.
- Affected
- >= 5.0.0, < 5.0.2, >= 4.0.0, < 4.2.2, >= 3.0.0, < 3.1.2, >= 2.0.0, < 2.0.2, >= 1.0.0, < 1.0.4
- Fixed in
- 5.0.2
- Weakness
- CWE-78
- Published
- 2019-01-04
- Source
- github
GHSANVDMITREreferencereferencereference
// ai model usageTracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.
Checked 2026-09-22 at 01:28 UTC. The most recent advisory here was published 2021-03-11. Updated continuously from NVD, GHSA, OSV and CNA feeds.