Skip to content

Bug report: Major security advisory #7159

@kjenney

Description

@kjenney

Priority

(Urgent) I can't use the CLI

Description

Github submitted an advisory for ALL versions of eslint-plugin-cli-microsoft365.

GHSA-w2fp-43hr-g757

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Steps to reproduce

npm install -g @pnp/cli-microsoft365
cd $(npm root -g)/@pnp/cli-microsoft365
npm audit

Expected results

Every vulnerability has "fix available" NOT "No fix available".

Actual results

eslint-plugin-cli-microsoft365 *
Severity: critical
Malware in eslint-plugin-cli-microsoft365 - GHSA-w2fp-43hr-g757
No fix available
eslint-rules
node_modules/eslint-plugin-cli-microsoft365

Diagnostics

No response

CLI for Microsoft 365 version

11.5.0

nodejs version

v18.20.8

Operating system (environment)

macOS

Shell

zsh

cli doctor

NA

Additional Info

NA

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions