@peertube/embed-api@0.0.4 vulnerabilities

API to communicate with the PeerTube player embed

Direct Vulnerabilities

Known vulnerabilities in the @peertube/embed-api package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Server-side Request Forgery (SSRF)

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) where local server files can be enumerated and media file with a guessable name can be leaked through the URL download procedure.

How to fix Server-side Request Forgery (SSRF)?

A fix was pushed into the master branch but not yet published.

>=0.0.0