# 4 high severity vulnerabilities while installing node-red@2.2.2 && 2.1.4

**URL:** <https://discourse.nodered.org/t/4-high-severity-vulnerabilities-while-installing-node-red-2-2-2-2-1-4/62542>\
**Category:** General\
**Created:** [12 May 2022 03:54 UTC](https://discourse.nodered.org/t/4-high-severity-vulnerabilities-while-installing-node-red-2-2-2-2-1-4/62542 "2022-05-12T03:54:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![xleili](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/xleili/32/61488_2.png) [@xleili](https://discourse.nodered.org/u/xleili)\
**Post date:** [12 May 2022 03:54 UTC](https://discourse.nodered.org/t/4-high-severity-vulnerabilities-while-installing-node-red-2-2-2-2-1-4/62542/1 "2022-05-12T03:54:15Z")

</div>

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/9/a921f3a3007901d5ce01f29aca56fcdcda08ac1e.png)

I reference node-red in my project at [TDengine/src/connector/node-red-contrib-tdengine at develop · taosdata/TDengine · GitHub](https://github.com/taosdata/TDengine/tree/develop/src/connector/node-red-contrib-tdengine) .I will always altered by github says:" prototype pollution in async" and this alert is decteced in pack-lock.json file.  
Can these vulnerabilities be resolved.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [12 May 2022 08:16 UTC](https://discourse.nodered.org/t/4-high-severity-vulnerabilities-while-installing-node-red-2-2-2-2-1-4/62542/2 "2022-05-12T08:16:34Z")

</div>

These issues will be resolved in 3.0.

They are limited to the Watch node - the fix was to rewrite the node to use a different underlying library. That type of change isn't one we would typically make in a fix release - but we could consider backporting it once we are certain it doesn't change any behaviour.

---

<div class="post-metadata">

**Author:** ![xleili](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/xleili/32/61488_2.png) [@xleili](https://discourse.nodered.org/u/xleili)\
**Post date:** [12 May 2022 08:53 UTC](https://discourse.nodered.org/t/4-high-severity-vulnerabilities-while-installing-node-red-2-2-2-2-1-4/62542/3 "2022-05-12T08:53:20Z")

</div>

Thanks for your explanation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [11 July 2022 08:53 UTC](https://discourse.nodered.org/t/4-high-severity-vulnerabilities-while-installing-node-red-2-2-2-2-1-4/62542/4 "2022-07-11T08:53:54Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
