VDB
Sign up
MEDIUM5.3

GHSA-46c4-8wrp-j99v

Improper Validation and Sanitization in url-parse

Quick fix

GHSA-46c4-8wrp-j99v — url-parse: upgrade to the fixed version with the command below.

npm install url-parse@1.4.5

Details

Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/url-parse
Introduced in: 0.1.0Fixed in: 1.4.5
Fixnpm install url-parse@1.4.5

References