VDB
Sign up
MEDIUM

GHSA-84hm-wfh8-c5pg

sse-channel: SSE Injection via unsanitized event fields

Quick fix

GHSA-84hm-wfh8-c5pg — sse-channel: upgrade to the fixed version with the command below.

npm install sse-channel@4.0.1

Details

### Impact

Implementations that allows user-provided values to be passed to `event`, `retry` or `id` fields would be susceptible to event spoofing, where an attacker could inject arbitrary messages into the stream.

- **Event Spoofing:** Attacker can inject arbitrary SSE events into the stream - **Client-side Manipulation:** Injected events can trigger unintended behavior in frontend JavaScript EventSource listeners - **Data Integrity:** Consumers of the SSE stream cannot distinguish injected events from legitimate ones

### Patches Patch available in v4.0.1.

### Workarounds Do not allow user data to control `event`, `retry` or `id` fields, and if you must - sanitize the input before passing it to `sse-channel`, stripping any newlines.

### Resources

https://github.com/rexxars/sse-channel/issues/42

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sse-channel
Introduced in: 0Fixed in: 4.0.1
Fixnpm install sse-channel@4.0.1

References