1.0.16
1 years ago
11 days ago
Known vulnerabilities in the better-call package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
better-call is a Better call is a tiny web framework for creating endpoints that can be invoked as a normal function or mounted to a router to be served by any web standard compatible server (like Bun, node, nextjs, sveltekit...) and also includes a typed RPC client for t Affected versions of this package are vulnerable to Use of Web Browser Cache Containing Sensitive Information via insufficient path sanitization in the request processing logic. An attacker can access sensitive user session data by crafting requests that mimic static asset paths, causing a CDN to cache and serve sensitive responses to unauthorized users. How to fix Use of Web Browser Cache Containing Sensitive Information? Upgrade | <1.0.12 |