Status
Fixed version
3.6.3-r1Status
Impact
This CVE is caused by esbuild which is a transitive dependency brought in under esbuild-loader. The fix exists upstream in main but has not been cut as part of a release as can be seen the the following PRs here: https://github.com/evanw/esbuild/issues/4056 and here: https://github.com/evanw/esbuild/pull/4057 Due to the transitive nature of esbuild, we must wait for upstream maintainers to cut a release of esbuild with the fix which will then be consumed by esbuild-loader.
Status