@genkit-ai/firebase@0.5.10 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the @genkit-ai/firebase package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • H
Race Condition

@genkit-ai/firebase is a Genkit AI framework plugin for Firebase including Firestore trace/state store and deployment helpers for Cloud Functions for Firebase.

Affected versions of this package are vulnerable to Race Condition via the asynchronous user engagement collection in the appendSpan and collectUserEngagement methods, where calls were not correctly awaited. Improper handling of asynchronous functions can lead to unexpected behavior or data inconsistencies during user engagement tracking.

How to fix Race Condition?

Upgrade @genkit-ai/firebase to version 0.9.1 or higher.

<0.9.1