Vulnerabilities/

url-parse Incorrectly parses URLs that include an '@

Severity:
Medium

Description

A specially crafted URL with an ‘@’ sign but empty user info and no hostname, when parsed with url-parse, url-parse will return the incorrect href.

Recommendation

Update the url-parse package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
url-parse
Anything's wrong? Let us know Last updated on September 11, 2023

This issue is available in SmartScanner Professional

See Pricing