CVE-2014-7192
Potential for Script Injection in syntax-error
EPSS 13.4%
Description
Versions of `syntax-error` prior to 1.1.1 are affected by a cross-site scripting vulnerability which may allow a malicious file to execute code when browserified. ## Recommendation Update to version 1.1.1 or later.
How to fix CVE-2014-7192
To remediate CVE-2014-7192, upgrade the affected package to a fixed version below.
- npm/syntax-error—upgrade to 1.1.1 or later
Is CVE-2014-7192 being exploited?
Moderate — EPSS is 13.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.1.1