@nestjs/devtools-integration@0.2.0 vulnerabilities

Nest - modern, fast, powerful node.js web framework (@devtools-integration)

  • latest version

    0.2.1

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    27 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @nestjs/devtools-integration package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Arbitrary Command Injection

    @nestjs/devtools-integration is a Nest - modern, fast, powerful node.js web framework (@devtools-integration)

    Affected versions of this package are vulnerable to Arbitrary Command Injection via the inspector/graph/interact endpoint, which accepts JSON input containing a code field and executes it in a Node.js vm.runInNewContext sandbox. An attacker can execute arbitrary code on the local machine by enticing a developer to visit a malicious website, which can then send crafted requests to the exposed local development server.

    How to fix Arbitrary Command Injection?

    Upgrade @nestjs/devtools-integration to version 0.2.1 or higher.

    <0.2.1