Vulnerabilities/

Path traversal in url-parse

Severity:
Medium

Description

url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

Recommendation

Update the url-parse package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
url-parse
Anything's wrong? Let us know Last updated on February 23, 2023

This issue is available in SmartScanner Professional

See Pricing