fast-xml-parser 4.1.3 - 5.3.5
Severity: high
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit) - https://github.com/advisories/GHSA-jmr7-xgp7-cmfj
fix available via `npm audit fix --force`
Will install @stoplight/prism-cli@4.12.0, which is a breaking change
node_modules/fast-xml-parser
@stoplight/prism-http-server 3.3.0-alpha.0 - 3.3.7 || >=4.13.0
Depends on vulnerable versions of @stoplight/prism-http
Depends on vulnerable versions of fast-xml-parser
node_modules/@stoplight/prism-http-server
@stoplight/prism-cli 3.3.3 - 3.3.7 || >=4.13.0
Depends on vulnerable versions of @stoplight/prism-http
Depends on vulnerable versions of @stoplight/prism-http-server
node_modules/@stoplight/prism-cli
lodash 4.0.0 - 4.17.21
Severity: moderate
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - https://github.com/advisories/GHSA-xxjr-mmjv-4gpg
fix available via `npm audit fix --force`
Will install @stoplight/prism-cli@4.12.0, which is a breaking change
node_modules/postman-collection/node_modules/lodash
postman-collection 0.5.1 - 5.2.0
Depends on vulnerable versions of lodash
node_modules/postman-collection
@stoplight/http-spec 2.5.8 - 7.1.0
Depends on vulnerable versions of postman-collection
node_modules/@stoplight/http-spec
@stoplight/prism-http 3.3.0-alpha.0 - 3.3.7 || >=5.7.0
Depends on vulnerable versions of @stoplight/http-spec
node_modules/@stoplight/prism-http
7 vulnerabilities (4 moderate, 3 high)