Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. ua-parser-js
  4. ›
  5. GHSA-236c-vhj4-gfxg

GHSA-236c-vhj4-gfxg: Duplicate Advisory: Embedded malware in ua-parser-js

May 25, 2022 (updated February 17, 2026)

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-pjwm-rvh2-c87w. This link is maintained to preserve external references.

Original Description

A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.

References

  • github.com/advisories/GHSA-236c-vhj4-gfxg
  • github.com/advisories/GHSA-pjwm-rvh2-c87w
  • github.com/faisalman/ua-parser-js/issues/536
  • nvd.nist.gov/vuln/detail/CVE-2021-4229
  • vuldb.com/?id.185453

Code Behaviors & Features

Detect and mitigate GHSA-236c-vhj4-gfxg with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.7.29 before 0.7.30, version 0.7.29, all versions starting from 0.8.0 before 0.8.1, version 0.8.0, all versions starting from 1.0.0 before 1.0.1, version 1.0.0

Fixed versions

  • 0.7.30
  • 0.8.1
  • 1.0.1

Solution

Upgrade to versions 0.7.30, 0.8.1, 1.0.1 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-829: Inclusion of Functionality from Untrusted Control Sphere
  • CWE-912: Hidden Functionality

Source file

npm/ua-parser-js/GHSA-236c-vhj4-gfxg.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 18 Feb 2026 12:21:21 +0000.