Homograph attack allows Unicode lookalike characters to bypass validation.
- Severity:
- High
Description
Attackers can deceive users into sending funds to an unintended address.
Recommendation
Update the base-x package to the latest compatible version. Followings are version details:
Affected version(s): **<= 3.0.10 = 4.0.0 = 5.0.0** Patched version(s): **3.0.11 4.0.1 5.0.1**
References
Related Issues
- hemmelig allows SSRF Filter bypass via Secret Request functionality - CVE-2025-69206
- Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - CVE-2025-59845
- Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - @apollo/sandbox - CVE-2025-59845
- IPX Allows Path Traversal via Prefix Matching Bypass - CVE-2025-54387
You might also like:
- Tags:
- npm
- base-x
Anything's wrong? Let us know Last updated on May 01, 2025


