Critical
Low
Medium
CVE-2025-59142
Overview
color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to red...
Critical
Low
Medium
No items found.