Vulnerability Found
unpkg depends on wrangler@4.7.0, which contains CVE-2026-0933 - an OS Command Injection vulnerability.
Affected Files
- packages/unpkg-app/package.json:
"wrangler": "^4.3.0"
- packages/unpkg-www/package.json:
"wrangler": "^4.3.0"
- pnpm-lock.yaml:946
Fix
Update to wrangler@4.59.1+:
pnpm update wrangler@4.59.1
Details
Vulnerability Found
unpkg depends on wrangler@4.7.0, which contains CVE-2026-0933 - an OS Command Injection vulnerability.
Affected Files
"wrangler": "^4.3.0""wrangler": "^4.3.0"Fix
Update to wrangler@4.59.1+:
Details