@solana/pay/.../pay@0.1.2 vulnerabilities

`@solana/pay` is a JavaScript library for facilitating commerce on Solana by using a token transfer URL scheme. The URL scheme ensures that no matter the wallet or service used, the payment request must be created and interpreted in one standard way.

  • latest version

    0.2.5

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @solana/pay package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Always-Incorrect Control Flow Implementation

    @solana/pay is a @solana/pay is a JavaScript library for facilitating commerce on Solana by using a token transfer URL scheme. The URL scheme ensures that no matter the wallet or service used, the payment request must be created and interpreted in one standard way.

    Affected versions of this package are vulnerable to Always-Incorrect Control Flow Implementation via the validateTransfer function, due to an edge case causing the validation logic to validate multiple payment transfers.

    How to fix Always-Incorrect Control Flow Implementation?

    Upgrade @solana/pay to version 0.2.1 or higher.

    <0.2.1