Description
When using this library as a way to programmatically communicate with Replit in a standalone fashion, if there are multiple failed attempts to contact Replit through a WebSocket, the library will attempt to communicate using a fallback poll-based proxy.
Recommendation
Update the @replit/crosis package to the latest compatible version. Followings are version details:
- Affected version(s): < 7.3.1
- Patched version(s): 7.3.1
References
Related Issues
- Exposure of Sensitive Information to an Unauthorized Actor in nanoid - CVE-2021-23566
- Potential Sensitive Cookie Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy - CVE-2022-31070
- Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy - CVE-2022-31069
- @kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor - CVE-2026-8766
You might also like:
- Tags:
- npm
- @replit/crosis
Anything's wrong? Let us know Last updated on July 24, 2023


