GHSA-29gp-92wp-94q8
Dashboard / Vulnerabilities / GHSA-29gp-92wp-94q8
Summary: react-dev-utils on Windows vulnerable to Remote Code Execution
Details: `react-dev-utils` on Windows is vulnerable to remote code execution. ## Recommendation Update to one of the following versions, depending on the release line that you are using. - 1.0.4 - 2.0.2 - 3.1.2 - 4.2.2 - 5.0.2 - 6.0.0-next.a671462c
References: https://nvd.nist.gov/vuln/detail/CVE-2018-6342, https://github.com/facebook/create-react-app/pull/4866, https://github.com/advisories/GHSA-29gp-92wp-94q8, https://github.com/facebook/create-react-app, https://github.com/facebook/create-react-app/releases/tag/v1.1.5, https://www.npmjs.com/advisories/695
Affected packages
Package
Name: react-dev-utils
Purl: pkg:npm/react-dev-utils
Affected ranges
Type: SEMVER
Events:
