Summary
The current version of browserstack-cypress-cli (1.36.3) includes a transitive dependency on [email protected], which has a known critical security vulnerability.
Vulnerability Details
Dependency Path
Impact
While this is a development dependency and the practical risk is mitigated in most controlled CI/CD environments (where archives are only extracted from trusted BrowserStack sources), security scanners and enterprise compliance tools flag this as a critical blocker, preventing adoption or requiring risk acceptance documentation.
Thank you for maintaining this tool!
Summary
The current version of
browserstack-cypress-cli(1.36.3) includes a transitive dependency on[email protected], which has a known critical security vulnerability.Vulnerability Details
[email protected]Dependency Path
Impact
While this is a development dependency and the practical risk is mitigated in most controlled CI/CD environments (where archives are only extracted from trusted BrowserStack sources), security scanners and enterprise compliance tools flag this as a critical blocker, preventing adoption or requiring risk acceptance documentation.
Thank you for maintaining this tool!