@solana/pay@0.2.0 vulnerabilities

`@solana/pay` is a JavaScript library for facilitating commerce on Solana by using a token transfer URL scheme. The URL scheme ensures that no matter the wallet or service used, the payment request must be created and interpreted in one standard way.

Direct Vulnerabilities

Known vulnerabilities in the @solana/pay package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Always-Incorrect Control Flow Implementation

@solana/pay is a @solana/pay is a JavaScript library for facilitating commerce on Solana by using a token transfer URL scheme. The URL scheme ensures that no matter the wallet or service used, the payment request must be created and interpreted in one standard way.

Affected versions of this package are vulnerable to Always-Incorrect Control Flow Implementation via the validateTransfer function, due to an edge case causing the validation logic to validate multiple payment transfers.

How to fix Always-Incorrect Control Flow Implementation?

Upgrade @solana/pay to version 0.2.1 or higher.

<0.2.1