VDB
Sign up
CRITICAL9.8

GHSA-5fjj-cfh2-ghc5

Server-Side Request Forgery and Inclusion of Functionality from Untrusted Control Sphere in jsreport

Quick fix

GHSA-5fjj-cfh2-ghc5 — jsreport: upgrade to the fixed version with the command below.

npm install jsreport@2.6.0

Details

An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jsreport
Introduced in: 0Fixed in: 2.6.0
Fixnpm install jsreport@2.6.0

References