GitHub identifies multiple nasty security vulnerabilities
GitHub identifies multiple nasty security vulnerabilities All vulnerabilities have apparently now been patched When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works. Cybersecurityresearchers have identified just over half a dozen vulnerabilities in a couple ofnpm packages, which can be exploited by attackers to execute arbitrary code on systems that permit installation of untrusted npm packages. The vulnerabilities were identified thanks to the initial reports by bug bounty hunters Robert Chen and Philip Papurt, who found security issues in thetarand@npmcli/arboristpackages....