-
-
Notifications
You must be signed in to change notification settings - Fork 9k
Security issues raised by lodash-es #7345
Copy link
Copy link
Closed
Labels
Internals: ParserStatus: ApprovedIs ready to be worked onIs ready to be worked onType: Bug / ErrorSomething isn't working or is incorrectSomething isn't working or is incorrect
Metadata
Metadata
Assignees
Labels
Internals: ParserStatus: ApprovedIs ready to be worked onIs ready to be worked onType: Bug / ErrorSomething isn't working or is incorrectSomething isn't working or is incorrect
Type
Fields
Give feedbackNo fields configured for issues without a type.
Description
Path: mermaid-11.12.1.tgz->parser-0.6.3.tgz->langium-3.3.1.tgz->chevrotain-11.0.3.tgz->lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->lodash-es-4.17.21.tgz
lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->parser-0.6.3.tgz->langium-3.3.1.tgz->chevrotain-allstar-0.3.1.tgz->lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->dagre-d3-es-7.0.13.tgz->lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->parser-0.6.3.tgz->langium-3.3.1.tgz->chevrotain-11.0.3.tgz->cst-dts-gen-11.0.3.tgz->lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->parser-0.6.3.tgz->langium-3.3.1.tgz->chevrotain-11.0.3.tgz->gast-11.0.3.tgz->lodash-es-4.17.21.tgz
CRITICAL: CVE-2025-13465
lodash-es should bump to 4.17.23
Steps to reproduce
install @mermaid-js/parser@0.6.3 or @mermaid-js/parser@latest
Screenshots
No response
Code Sample
Setup
Suggested Solutions
No response
Additional Context
No response