{"id":"GHSA-mh6f-8j2x-4483","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mh6f-8j2x-4483","summary":"Critical severity vulnerability that affects event-stream and flatmap-stream","details":"The NPM package `flatmap-stream` is considered malicious.  A malicious actor added this package as a dependency to the NPM `event-stream` package in version `3.3.6`.  Users of `event-stream` are encouraged to downgrade to the last non-malicious version, `3.3.4`, or upgrade to the latest  4.x version. \n\nUsers of `flatmap-stream` are encouraged to remove the dependency entirely.\n","published":"2018-11-26T23:58:21Z","modified":"2021-09-15T20:08:26Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"event-stream","fixedVersion":"4.0.0"},{"ecosystem":"npm","name":"flatmap-stream","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/dominictarr/event-stream/issues/116"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mh6f-8j2x-4483"},{"type":"PACKAGE","url":"https://github.com/dominictarr/event-stream"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-15T20:08:26Z"}}