Versions of syntax-error prior to 1.1.1 are affected by a cross-site scripting vulnerability which may allow a malicious file to execute code when browserified.
// recommendationUpdate to version 1.1.1 or later.
1 known vulnerability, worst severity HIGH.
0 direct dependencies
none carry a known advisory
Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.
severity band, no base score published
chance of exploitation in 30 days, 96th percentile of all CVEs
CyberXYZ composite, a working exploit is published
fig. 01 — GHSA-5726-g6r9-5f22, the advisory selected below
Versions of syntax-error prior to 1.1.1 are affected by a cross-site scripting vulnerability which may allow a malicious file to execute code when browserified.
// recommendationUpdate to version 1.1.1 or later.
Checked 2026-10-04 at 01:07 UTC. The most recent advisory here was published 2017-10-24. Updated continuously from NVD, GHSA, OSV and CNA feeds.