Skip to content

The transitive dependent package System.Text.RegularExpressions 4.3.0 has a vulnerability. #66

@guogangj

Description

@guogangj

Visual Studio 2022 shows this warning:
image
I traced the dependency chain and found that the problematic package System.Text.RegularExpressions 4.3.0 is indirectly referenced from SharpDocx. Its dependency chain is as follows:

SharpDocx.2.4.0
  => Microsoft.CodeAnalysis.CSharp.2.10.0
    =>Microsoft.CodeAnalysis.Common.2.10.0
      =>System.Xml.XDocument.4.3.0
        => System.Xml.ReaderWriter.4.3.0
          => System.Text.RegularExpressions.4.3.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions