Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

version 3.6.0 contains prismjs which is vulnerable to CVE-2024-53382 #75

Closed
marvingreeven opened this issue Mar 21, 2025 · 1 comment
Closed

Comments

@marvingreeven
Copy link

marvingreeven commented Mar 21, 2025

version 3.6.0 contains prismjs ~1.27.0 (which resolves into version 1.27.0).

Is it possible to bumb prismjs to ^1.30.0 (which resolves into version 1.30.0, <2.0.0) in this version?

Background:
swagger-ui refers to react-syntax-highlighter which refers to "refractor": "^3.6.0".
It seems like the project is not longer maintained.

A patch to 3.6.1 would help us a lot!

@wooorm
Copy link
Owner

wooorm commented Mar 24, 2025

Hi! Use v4 or v5, it’s been years. See also the readme on how to turn things into react nodes: https://github.com/wooorm/refractor#example-turning-hast-into-react-nodes.

@wooorm wooorm closed this as completed Mar 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants