npm vulnerability intelligence
minimist
NPM Package
Vulnerability Check
parse argument options
Critical MIT
v1.2.8
Vulnerability Analysis
OSV Live
minimist
v1.2.8 · MIT · 133,004,716 dl/wk
Advisory Breakdown
Severity Rating
Critical2 advisories
Critical
Weekly downloads
133,004,716
Total advisories
2
Latest version
1.2.8
License
MIT
Known advisories
OSV records for the npm ecosystem
GHSA-vh95-rmgr-6w4m CVE-2020-7598 moderate
Prototype Pollution in minimist
Affected: >=0 <0.2.1, >=1.0.0 <1.2.3 Fixed in: 0.2.1, 1.2.3 Updated Mar 13, 2026
View source
GHSA-xvch-5gv4-984h CVE-2021-44906 critical
Prototype Pollution in minimist
Affected: >=1.0.0 <1.2.6, >=0 <0.2.4 Fixed in: 1.2.6, 0.2.4 Updated Mar 13, 2026
View source
Checked Jun 24, 2026, 6:56 PM from npm and OSV.dev
Package metadata
From the npm registry
- Package name
- minimist
- Ecosystem
- npm
- Latest version
- 1.2.8
- License
- MIT
- Weekly downloads
- 133,004,716
- Repository
- Open repository
Remediation boundary
What RequestGuard does — and doesn't — cover
RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.
Data from npm registry and OSV.dev · Checked 6/24/2026, 6:56:41 PM