VDB
Sign up
HIGH7.5

GHSA-32j9-6qqm-mq9g

Unhandled case in node-lmdb

Quick fix

GHSA-32j9-6qqm-mq9g — node-lmdb: upgrade to the fixed version with the command below.

npm install node-lmdb@0.9.7

Details

The package node-lmdb before 0.9.7 is vulnerable to Denial of Service (DoS) when defining a non-invokable `ToString` value, which will cause a crash during type check.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-lmdb
Introduced in: 0Fixed in: 0.9.7
Fixnpm install node-lmdb@0.9.7

References