MEDIUM5.3
GHSA-rf54-44jr-q5vf
Improper Input Validation in url-js
Quick fix
GHSA-rf54-44jr-q5vf — url-js: upgrade to the fixed version with the command below.
npm install url-js@2.1.0Details
The package url-js before 2.1.0 is vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be spoofed. http://\\\\\\\\localhost and http://localhost are the same URL. However, the hostname is not parsed as localhost, and the backslash is reflected as it is.
Are you affected?
Enter the version of the package you're using.