VDB
Sign up
HIGH

GHSA-9q64-mpxx-87fg

Open Redirect in ecstatic

Quick fix

GHSA-9q64-mpxx-87fg — ecstatic: upgrade to the fixed version with the command below.

npm install ecstatic@2.2.2

Details

Versions of `ecstatic` prior to 4.1.2, 3.3.2 or 2.2.2 are vulnerable to Open Redirect. The package fails to validate redirects, allowing attackers to craft requests that result in an `HTTP 301` redirect to any other domains.

## Recommendation

If using `ecstatic` 4.x, upgrade to 4.1.2 or later. If using `ecstatic` 3.x, upgrade to 3.3.2 or later. If using `ecstatic` 2.x, upgrade to 2.2.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ecstatic
Introduced in: 0Fixed in: 2.2.2
Fixnpm install ecstatic@2.2.2
npm/ecstatic
Introduced in: 3.0.0Fixed in: 3.3.2
Fixnpm install ecstatic@3.3.2
npm/ecstatic
Introduced in: 4.0.0Fixed in: 4.1.2
Fixnpm install ecstatic@4.1.2

References