Skip to content

Is GHSA-x5gf-qvw8-r2rm still a problem? #6075

@TomFryersMidsummer

Description

@TomFryersMidsummer

My guess, reading through all the associated issues, pull requests and source code, is no.

However, given that the fix for this vulnerability was in PR 5971 and the change-log for 6.0.10 contains the entry ‘revert #5971 #6031’, this isn't very clear. Indeed, GHSA-x5gf-qvw8-r2rm now marks every version of PM2 as vulnerable.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions