Color-String是Josh Junon个人开发者的一个解析和生成 CSS 颜色字符串的库。 color-string 2.1.1版本存在安全漏洞,该漏洞源于恶意软件有效载荷注入,可能导致浏览器环境中加密货币交易重定向。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Qix- | color-string | = 2.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-59140 | backslash@0.2.1 contains malware after npm account takeover | |
| CVE-2025-59141 | simple-swizzle@0.2.3 contains malware after npm account takeover | |
| CVE-2025-59162 | color-convert@3.1.1 contains malware after npm account takeover | |
| CVE-2025-59331 | is-arrayish@0.3.3 contains malware after npm account takeover | |
| CVE-2025-59330 | error-ex@1.3.3 contains malware after npm account takeover | |
| CVE-2025-59143 | color@5.0.1 contains malware after npm account takeover |
No comments yet