Package
kibana-8.19-bitnami
Component
@ai-sdk/provider-utils
Latest update
4.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable component is the @ai-sdk/provider-utils npm package, a transitive dependency resolved via the ai package in the upstream lockfile. GHSA-866g-f22w-33x8 lists all released versions up to and including 3.0.97 as affected, with no patched version published. Until a fixed @ai-sdk/provider-utils release is published and adopted in the upstream dependency chain, this vulnerability cannot be remediated with a dependency pin.
Status