Upstream has issued an advisory on June 20: https://nodesecurity.io/advisories/118 The issue is fixed upstream in 3.0.2. Mageia 5 may also be affected.
not valid on mga5 from what i saw. Fixed on mga6
Status: NEW => RESOLVEDCC: (none) => mageiaVersion: Cauldron => 5Resolution: (none) => FIXED