@supabase/auth-js@2.58.1-canary.0 vulnerabilities

Official client library for Supabase Auth

  • latest version

    2.72.0

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    8 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @supabase/auth-js package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Directory Traversal

    @supabase/auth-js is an Official client library for Supabase Auth

    Affected versions of this package are vulnerable to Directory Traversal due to improper validation of user-supplied input in the functions getUserById, deleteUser, updateUserById, listFactors, and deleteFactor. An attacker can manipulate the URL path to access unauthorized functions by supplying malformed inputs that are not valid UUIDs.

    How to fix Directory Traversal?

    Upgrade @supabase/auth-js to version 2.70.0-rc.7 or higher.

    <2.70.0-rc.7