VDB
Sign up
CRITICAL9.8

GHSA-r24h-634p-m72x

Validation Bypass in schema-inspector

Quick fix

GHSA-r24h-634p-m72x — schema-inspector: upgrade to the fixed version with the command below.

npm install schema-inspector@1.6.9

Details

In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/schema-inspector
Introduced in: 0Fixed in: 1.6.9
Fixnpm install schema-inspector@1.6.9

References