Description
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation.
Recommendation
Update the validator package to the latest compatible version. Followings are version details:
- Affected version(s): < 13.15.22
- Patched version(s): 13.15.22
References
Could your website be exposed too?
SmartScanner can check your website for Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements and gives you actionable findings to investigate.
Start a free scanRelated Issues
- AngularJS Incomplete Filtering of Special Elements vulnerability - CVE-2025-2336
- DiracX-Web is vulnerable to attack through an Open Redirect on its login page - CVE-2025-54066
- Fiora chat user avatar is vulnerable to XSS via SVG files - CVE-2025-56514
- MCPHub's ServerController is vulnerable to Command Injection - CVE-2025-11285


