CVE-2022-37620 html-minifier-terser dependency vulnerability

Author: CodeByCalvinCreated May 20, 2025Updated Sep 17, 2026

OWASP is currently throwing the following security vulnerability error from the latest version of html-webpack-plugin (5.6.3):

One or more dependencies were identified with vulnerabilities that have a CVSS score greater than or equal to '7.0': 

html-minifier-terser:^6.0.2 (pkg:npm/[email protected], cpe:2.3:a:terser:html-minifier-terser:6.1.0:*:*:*:*:*:*:*): CVE-2022-37620(7.5)

See the dependency-check report for more details.

Source: jantimon/html-webpack-plugin