@nestjs/common@11.0.13 vulnerabilities

Nest - modern, fast, powerful node.js web framework (@common)

  • latest version

    11.1.0

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @nestjs/common package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Arbitrary Code Injection

    @nestjs/common is a Nest - modern, fast, powerful node.js web framework (@common)

    Affected versions of this package are vulnerable to Arbitrary Code Injection via the FileTypeValidator function due to improper MIME Type Validation. An attacker can execute arbitrary code by sending a crafted payload in the Content-Type header of a request.

    Note:

    The FileTypeValidator documentation specifically mentions that it is vulnerable and provides security enhancement recommendations.

    How to fix Arbitrary Code Injection?

    Upgrade @nestjs/common to version 11.0.16 or higher.

    <11.0.16