VDB
Sign up
CRITICAL9.1

GHSA-hgjh-723h-mx2j

Authorization Bypass Through User-Controlled Key in url-parse

Quick fix

GHSA-hgjh-723h-mx2j — url-parse: upgrade to the fixed version with the command below.

npm install url-parse@1.5.8

Details

url-parse prior to version 1.5.8 is vulnerable to Authorization Bypass Through User-Controlled Key.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/url-parse
Introduced in: 0Fixed in: 1.5.8
Fixnpm install url-parse@1.5.8

References