TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Found a Vulnerability In NPM Package

1 pointsby daudmalik06over 3 years ago

2 comments

heijmansover 3 years ago
It was actually reported on (or before) Jan 3rd.<p>See <a href="https:&#x2F;&#x2F;security.snyk.io&#x2F;vuln&#x2F;SNYK-JS-EXTEND2-2320315" rel="nofollow">https:&#x2F;&#x2F;security.snyk.io&#x2F;vuln&#x2F;SNYK-JS-EXTEND2-2320315</a> .
daudmalik06over 3 years ago
A high severity vulnerability has been found in a widely used npm package &quot;extend2&quot; with over 46K weekly downloads.