VDB
Sign up
HIGH

GHSA-gg6x-448q-pqqm

Avenwu Whistle Cross-Site Request Forgery (CSRF)

Details

Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/whistle
Introduced in: 0

No fixed version published yet for whistle (npm). Pin to a known-safe version or switch to an alternative.

References