This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| pac-resolver(npm) | 0 | 5.0.0 | N/A |
| degenerator(npm) | 0 | 3.0.1 | N/A |
CVSS Metrics