VYPR

Shiba

by Shiba Project

CVEs (2)

  • CVE-2020-7738HigOct 2, 2020
    risk 0.54cvss 8.3epss 0.02

    All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load() of the package js-yaml instead of its secure replacement , safeLoad().

  • CVE-2017-1000491MedJan 3, 2018
    risk 0.33cvss 6.1epss 0.01

    Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.