@peertube/embed-api@0.0.7 vulnerabilities

API to communicate with the PeerTube player embed

Direct Vulnerabilities

Known vulnerabilities in the @peertube/embed-api package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Server-side Request Forgery (SSRF)

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) where local server files can be enumerated and media file with a guessable name can be leaked through the URL download procedure.

How to fix Server-side Request Forgery (SSRF)?

A fix was pushed into the master branch but not yet published.

>=0.0.0