HIGH7.5
GHSA-43wq-xrcm-3vgr
@discordjs/opus vulnerable to Denial of Service
Details
All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toString to several different functions. Exploiting this vulnerability could lead to a process crash.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@discordjs/opus
Introduced in:
0No fixed version published yet for @discordjs/opus (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21521[ADVISORY]
- https://gist.github.com/dellalibera/98c48fd74bb240adbd7841a5c02aba9e[WEB]
- https://github.com/discordjs/opus[PACKAGE]
- https://github.com/discordjs/opus/blob/814e500c2785c5207ace19650192629beba2728b/src/node-opus.cc#L47[WEB]
- https://security.snyk.io/vuln/SNYK-JS-DISCORDJSOPUS-6370643[WEB]