Description
Using a CDN that caches (/**/*.png, /**/*.json, /**/*.css, etc…) requests, a cache deception can emerge. This could lead to unauthorized access to user sessions and personal data when cached responses are served to other users.
Recommendation
Update the better-call package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.12
- Patched version(s): 1.0.12
References
Related Issues
- Failure to sanitize quotes which can lead to sql injection in squel - Vulnerability
- content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE - CVE-2025-55164
- Axios: Prototype pollution gadgets can alter axios request construction - Vulnerability
- javascript-deobfuscator crafted payload can lead to code execution - CVE-2024-36120
You might also like:
- Tags:
- npm
- better-call
Anything's wrong? Let us know Last updated on July 11, 2025


