-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from two key components: 1) The install.js script that executed node-pre-gyp to fetch binaries from a hardcoded S3 URL. 2) The package.json configuration enabling this behavior. The commit diff shows these were removed/patched in v1.2.11. The node-pre-gyp integration created an insecure code loading path by design, making these entry points vulnerable to supply chain attacks if the S3 bucket was compromised.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| fsevents | npm | <= 1.2.10 | 1.2.11 |
Ongoing coverage of React2Shell