CRITICAL9.8
GHSA-5fjj-cfh2-ghc5
Server-Side Request Forgery and Inclusion of Functionality from Untrusted Control Sphere in jsreport
Quick fix
GHSA-5fjj-cfh2-ghc5 — jsreport: upgrade to the fixed version with the command below.
npm install jsreport@2.6.0Details
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.
Are you affected?
Enter the version of the package you're using.