VYPR

npm package

djv

pkg:npm/djv

Vulnerabilities (1)

  • CVE-2020-28464Jan 4, 2021
    affected < 2.1.4fixed 2.1.4

    This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.