Vulnerabilities/

Unintended Require in larvitbase-api

Severity:
High

Description

Versions of larvitbase-api prior to 0.5.4 are vulnerable to an Unintended Require. The package exposes an API endpoint and passes a GET parameter unsanitized to an require() call. This allows attackers to execute any .js file in the same folder as the server is running.

Recommendation

Update the larvitbase-api package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
larvitbase-api
Anything's wrong? Let us know Last updated on September 11, 2023

This issue is available in SmartScanner Professional

See Pricing