Skip to content

CVE-2023-26136 tough-cookie Vulnerability  #124

@heena-ap

Description

@heena-ap

This package has a dependency on two deprecated packages - request and request-promise
Both of these packages depend on tough-cookie package.
And on npm audit we are getting this vulnerability =>
tough-cookie <4.1.3
Severity: moderate
tough-cookie Prototype Pollution vulnerability - https://github.com/advisories/GHSA-72xf-g2v4-qvf3

Output of npm ls tough-cookie =>
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions