Vulnerabilities/

Server-Side Request Forgery in @uppy/companion

Severity:
High

Description

The @uppy/companion npm package before versions 1.13.2 and 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.

Recommendation

Update the @uppy/companion package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@uppy/companion
Anything's wrong? Let us know Last updated on September 13, 2023

This issue is available in SmartScanner Professional

See Pricing