Vulnerabilities/

sse-channel: SSE Injection via unsanitized event fields

Severity:
Medium

Description

Implementations that allows user-provided values to be passed to event, retry or id fields would be susceptible to event spoofing, where an attacker could inject arbitrary messages into the stream.

Recommendation

Update the sse-channel package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
sse-channel
Anything's wrong? Let us know Last updated on May 13, 2026