Vulnerabilities/

Feathers socket handler allows abusing implicit toString (GHSA-hhr9-rh25-hvf9)

Severity:
High

Description

Feathers socket handler did not catch invalid string conversion errors like:

Causing the NodeJS process to crash when sending an unexpected Socket.io message like

Recommendation

Update the @feathersjs/socketio package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@feathersjs/socketio
Anything's wrong? Let us know Last updated on November 07, 2023

This issue is available in SmartScanner Professional

See Pricing