Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Im confused, did the update from last week for the RCE bug also include fixes for these new CVEs or will I need to update again? npm audit says theres no issues




is it not obvious?

> These issues are present in the patches published last week.

> The patches published last week are vulnerable.

> If you already updated for the Critical Security Vulnerability, you will need to update again.


GitHub has to review the advisories and publish it for it to show in `npm audit`, so it's delayed.

You need to update again.

This could be the Next.js motto.

You need to upgrade again, and no the docs aren’t finished (and they won’t be before the new new version).

My Umami stats box got "pwned" about 15 mins after the last CVE was published and I spent an hour or so cleaning up that mess and upgrading everything. Not looking forward to doing it again today.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: