Vulnerabilities/

Code Injection in jsen

Severity:
High

Description

This affects all versions of package jsen. If an attacker can control the schema file, it could run arbitrary JavaScript code on the victim machine. In the module description and README file there is no mention about the risks of untrusted schema files, so it is assumed that this is applicable.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
jsen
Anything's wrong? Let us know Last updated on September 11, 2023

This issue is available in SmartScanner Professional

See Pricing