All the vulnerabilities related to the version 1.0.0 of the package
tschaub gh-pages vulnerable to prototype pollution
Prototype pollution vulnerability in tschaub gh-pages via the partial variable in util.js.
Prototype Pollution in async
A vulnerability exists in Async through 3.2.1 for 3.x and through 2.6.3 for 2.x (fixed in 3.2.2 and 2.6.4), which could let a malicious user obtain privileges via the mapValues()
method.
Out-of-bounds Read in base64url
Versions of base64url
before 3.0.0 are vulnerable to to out-of-bounds reads as it allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
Update to version 3.0.0 or later.