access-policy@3.1.0 vulnerabilities

Encodes and decodes policy JSON files for use with web applications.

Direct Vulnerabilities

Known vulnerabilities in the access-policy package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary Code Execution

access-policy is a package that encodes and decodes policy JSON files for use with web applications.

Affected versions of this package are vulnerable to Arbitrary Code Execution. User input provided to the template function is executed by the eval function resulting in code execution.

How to fix Arbitrary Code Execution?

There is no fixed version for access-policy.

*