VDB
Sign up
MEDIUM5.4

GHSA-rfhr-62xp-2fp2

Open Redirect in trailing-slash

Quick fix

GHSA-rfhr-62xp-2fp2 — trailing-slash: upgrade to the fixed version with the command below.

npm install trailing-slash@2.0.1

Details

The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web server uses relative URLs instead of absolute URLs.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/trailing-slash
Introduced in: 0Fixed in: 2.0.1
Fixnpm install trailing-slash@2.0.1

References