Summary
The current version of browserstack-cypress-cli (1.36.3) includes a transitive dependency on decompress-tar@4.1.1, which has a known critical security vulnerability.
Vulnerability Details
Dependency Path
browserstack-cypress-cli@1.36.3
└─┬ decompress@4.2.1
├── decompress-tar@4.1.1 ⚠️ VULNERABLE
├─┬ decompress-tarbz2@4.1.1
│ └── decompress-tar@4.1.1 deduped
└─┬ decompress-targz@4.1.1
└── decompress-tar@4.1.1 deduped
Impact
While this is a development dependency and the practical risk is mitigated in most controlled CI/CD environments (where archives are only extracted from trusted BrowserStack sources), security scanners and enterprise compliance tools flag this as a critical blocker, preventing adoption or requiring risk acceptance documentation.
Thank you for maintaining this tool!
Summary
The current version of
browserstack-cypress-cli(1.36.3) includes a transitive dependency ondecompress-tar@4.1.1, which has a known critical security vulnerability.Vulnerability Details
decompress-tar@4.1.1Dependency Path
Impact
While this is a development dependency and the practical risk is mitigated in most controlled CI/CD environments (where archives are only extracted from trusted BrowserStack sources), security scanners and enterprise compliance tools flag this as a critical blocker, preventing adoption or requiring risk acceptance documentation.
Thank you for maintaining this tool!