Advisories for Npm/React-Dev-Utils package

2021
2018

Cross-Site Request Forgery (CSRF)

react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the server (either via CSRF or by direct request) to execute arbitrary commands on the targeted system.