VDB
Sign up
MEDIUM6.5

GHSA-5h5v-hw44-f6gg

Oceanic allows unsanitized user input to lead to path traversal in URLs

Quick fix

GHSA-5h5v-hw44-f6gg — oceanic.js: upgrade to the fixed version with the command below.

npm install oceanic.js@1.10.4

Details

### Impact Input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially crafted input such as `../../../channels/{id}` being normalized into the url `/api/v10/channels/{id}`, and deleting a channel rather than removing a ban.

### Workarounds * Sanitizing user input, ensuring strings are valid for the purpose they are being used for. * Encoding input with `encodeURIComponent` before providing it to the library.

### References OceanicJS/Oceanic@8bf8ee8373b8c565fbdbf70a609aba4fbc1a1ffe

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/oceanic.js
Introduced in: 0Fixed in: 1.10.4
Fixnpm install oceanic.js@1.10.4

References