VDB
Sign up
MEDIUM6.5

GHSA-8v38-pw62-9cw2

url-parse Incorrectly parses URLs that include an '@'

Quick fix

GHSA-8v38-pw62-9cw2 — url-parse: upgrade to the fixed version with the command below.

npm install url-parse@1.5.7

Details

A specially crafted URL with an '@' sign but empty user info and no hostname, when parsed with url-parse, url-parse will return the incorrect href. In particular,

```js parse(\"http://@/127.0.0.1\") ``` Will return: ```yaml { slashes: true, protocol: 'http:', hash: '', query: '', pathname: '/127.0.0.1', auth: '', host: '', port: '', hostname: '', password: '', username: '', origin: 'null', href: 'http:///127.0.0.1' } ``` If the 'hostname' or 'origin' attributes of the output from url-parse are used in security decisions and the final 'href' attribute of the output is then used to make a request, the decision may be incorrect.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/url-parse
Introduced in: 1.0.0Fixed in: 1.5.7
Fixnpm install url-parse@1.5.7

References