-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| unicode-json | npm | < 2.0.0 | 2.0.0 |
The provided vulnerability description and references indicate that unicode-json versions <2.0.0 insecurely download resources over HTTP. However, no actual code snippets, patch diffs, or function names are provided in the advisory details or NVD/CVE entries. Runtime detection requires knowing the exact function(s) responsible for initiating HTTP requests (e.g., functions calling http.get), but this information is absent from the provided data. Without concrete evidence of the vulnerable code structure or patched functions, we cannot confidently identify specific function signatures for runtime profiling.
Ongoing coverage of React2Shell