VDB
Sign up
CRITICAL9.8

GHSA-7f3x-x4pr-wqhj

Server-Side Request Forgery in parse-url

Quick fix

GHSA-7f3x-x4pr-wqhj — parse-url: upgrade to the fixed version with the command below.

npm install parse-url@6.0.1

Details

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/parse-url
Introduced in: 0Fixed in: 6.0.1
Fixnpm install parse-url@6.0.1

References