Summary
The twilio package depends on jsonwebtoken@9.0.2 which in turn uses jws@3.2.2, which has a HIGH severity vulnerability (GHSA-869p-cjfg-cm3x) regarding improper HMAC signature verification.
Vulnerability Details
- Package: jws
-
- Vulnerable versions: <3.2.3
-
-
- Patched versions: >=3.2.3
-
Request
Please update jsonwebtoken to a version that uses jws@3.2.3 or later, or update the dependency chain to resolve this vulnerability.
Current Path
`twilio@5.11.1