Skip to content

Security issue in dependency Use of eval in "node_modules/lottie-web/build/player/lottie.js" is strongly discouraged as it poses security risks and may cause issues with minification. #381

@JustFly1984

Description

@JustFly1984

I have an app using react three fiber, which depends on three.js and consequently on three-stdlib.

I'm auditing security and finding this issue in lottie-web, which is not maintained for a while, and this issue is not fixes even if there is a bunch of PR's from community. airbnb/lottie-web#2927

I've created an issue in three.js

mrdoob/three.js#29572

but was redirected to this repo.

Please get rid of lottie-web for next version release. using eval is very bad security issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    duplicateThis issue or pull request already existsreleased

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions