@pdfme/common@5.3.16-dev.9 vulnerabilities

TypeScript base PDF generator and React base UI. Open source, developed by the community, and completely free to use under the MIT license!

  • latest version

    5.4.2

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    9 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @pdfme/common package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    @pdfme/common is a TypeScript base PDF generator and React base UI. Open source, developed by the community, and completely free to use under the MIT license!

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the validateAST function in the expression.ts file. An attacker can execute arbitrary JavaScript code, steal sensitive information, or modify application behavior by crafting malicious input that bypasses sandbox restrictions and manipulates prototype accessor methods.

    How to fix Cross-site Scripting (XSS)?

    Upgrade @pdfme/common to version 5.4.1 or higher.

    >=5.2.0 <5.4.1