This advisory was withdrawn by its CNA (Snyk).
All versions of package msgpack are vulnerable to Deserialization of Untrusted Data via the unpack function. This does not affect the similarly named package @msgpack/msgpack.
{
"cwe_ids": [
"CWE-502"
],
"github_reviewed": true,
"github_reviewed_at": "2021-07-26T17:38:45Z",
"nvd_published_at": "2021-07-21T17:15:00Z",
"severity": "CRITICAL"
}