npm vulnerability intelligence

eslint-scope NPM Package
Vulnerability Check

ECMAScript scope analyzer for ESLint

Critical BSD-2-Clause v9.1.2
Vulnerability Analysis OSV Live

eslint-scope

v9.1.2 · BSD-2-Clause · 188,387,762 dl/wk

Advisory Breakdown

Critical 1
High 0
Moderate 0
Low 0

Severity Rating

Critical

1 advisory

Critical

Weekly downloads

188,387,762

Total advisories

1

Latest version

9.1.2

License

BSD-2-Clause

Known advisories

OSV records for the npm ecosystem

1
GHSA-hxxf-q3w9-4xgw critical

Malicious Package in eslint-scope

Affected: >=3.7.2 <3.7.3, >=5.0.2 <6.0.0 Fixed in: 3.7.3, 6.0.0 Updated Sep 14, 2021
View source

Checked Jun 25, 2026, 11:17 AM from npm and OSV.dev

Package metadata

From the npm registry

Package name
eslint-scope
Ecosystem
npm
Latest version
9.1.2
License
BSD-2-Clause
Weekly downloads
188,387,762

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 6/25/2026, 11:17:32 AM