PT-2022-28175 · Npm · Coloros

Published

2022-01-12

·

Updated

2022-01-12

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions colors package versions prior to 0.26.1
Description The vulnerability is related to the colors package, which caused zalgo-like output, breaking servers. Only NPM users who recently upgraded or installed the NPM package are affected. Docker users seem not to be affected as the dependencies were bundled at the time of the build.
Recommendations For versions prior to 0.26.1, upgrade to the latest patch, version 0.26.1, to resolve the issue. As a temporary workaround, consider avoiding the use of the colors package until the issue is resolved.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-2W8G-M5J8-7M87

Affected Products

Coloros