dectalk-tts@1.0.0 vulnerabilities

API wrapper for the Dectalk TTS system

  • latest version

    1.0.1

  • latest non vulnerable version

  • first published

    11 months ago

  • latest version published

    11 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the dectalk-tts package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Channel Accessible by Non-Endpoint ('Man-in-the-Middle')

    dectalk-tts is an API wrapper for the Dectalk TTS system

    Affected versions of this package are vulnerable to Channel Accessible by Non-Endpoint ('Man-in-the-Middle') due to the use of unencrypted HTTP for network requests to a third-party API. This allows an attacker to intercept and modify traffic, leading to potential man-in-the-middle (MITM) attacks.

    How to fix Channel Accessible by Non-Endpoint ('Man-in-the-Middle')?

    Upgrade dectalk-tts to version 1.0.1 or higher.

    <1.0.1