Vulnerabilities/

Elysia affected by arbitrary code injection through cookie config

Severity:
High

Description

Arbitrary code execution from cookie config. If dynamic cookies are enabled (ie there exists a schema for cookies), the cookie config is injected into the compiled route without first being sanitised.

Recommendation

Update the elysia package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
elysia
Anything's wrong? Let us know Last updated on December 09, 2025