Skip to content

Security: jsonwebtoken dependency uses vulnerable jws@3.2.2 #1165

@MAlkabbani

Description

@MAlkabbani

Summary

The twilio package depends on jsonwebtoken@9.0.2 which in turn uses jws@3.2.2, which has a HIGH severity vulnerability (GHSA-869p-cjfg-cm3x) regarding improper HMAC signature verification.

Vulnerability Details

  • Package: jws
    • Vulnerable versions: <3.2.3
      • Patched versions: >=3.2.3

Request

Please update jsonwebtoken to a version that uses jws@3.2.3 or later, or update the dependency chain to resolve this vulnerability.

Current Path

`twilio@5.11.1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions