Vulnerabilities/

TurboBoost Commands vulnerable to arbitrary method invocation

Severity:
High

Description

TurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren’t as robust as they should be.

Recommendation

Update the @turbo-boost/commands package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@turbo-boost/commands
Anything's wrong? Let us know Last updated on March 18, 2024

This issue is available in SmartScanner Professional

See Pricing