# Js-yaml 3.13.1 vulnerability

**URL:** <https://discourse.nodered.org/t/js-yaml-3-13-1-vulnerability/11666>\
**Category:** General\
**Created:** [29 May 2019 09:43 UTC](https://discourse.nodered.org/t/js-yaml-3-13-1-vulnerability/11666 "2019-05-29T09:43:02Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Louise](https://avatars.discourse-cdn.com/v4/letter/l/ed8c4c/32.png) [@Louise](https://discourse.nodered.org/u/Louise)\
**Post date:** [29 May 2019 09:43 UTC](https://discourse.nodered.org/t/js-yaml-3-13-1-vulnerability/11666/1 "2019-05-29T09:43:02Z")

</div>

Hello everyone,

I was installing a custom node and I got a "found 1 high severity vulnerability". Using npm audit I found out that the vulnerability is js-yaml and for more information I had to look here: [https://www.npmjs.com/advisories/813](https://www.npmjs.com/advisories/813). So the advice that this website gave me is to upgrade to js-yaml 3.13.1, however I already have version 3.13.1. Should I just ignore this problem because my custom node works fine?
