CRITICAL9.8
GHSA-hw46-vg6w-88fj
replicator vulnerable to Deserialization of Untrusted Data
Quick fix
GHSA-hw46-vg6w-88fj — replicator: upgrade to the fixed version with the command below.
npm install replicator@1.0.4Details
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-33420[ADVISORY]
- https://github.com/inikulin/replicator/issues/16[WEB]
- https://github.com/inikulin/replicator/pull/17[WEB]
- https://github.com/inikulin/replicator/commit/2c626242fb4a118855262c64b5731b2ce98e521b[WEB]
- https://advisory.checkmarx.net/advisory/CX-2021-4787[WEB]
- https://github.com/inikulin/replicator[PACKAGE]