fuels@0.0.0-pr-3278-20241008191301 vulnerabilities

Fuel TS SDK

  • latest version

    0.97.2

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    15 days ago

  • licenses detected

    • >=0.0.0-master-0177b66 <0.0.0-test; >=0.1.0
  • Direct Vulnerabilities

    Known vulnerabilities in the fuels package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Improper Input Validation

    fuels is a Fuel TS SDK

    Affected versions of this package are vulnerable to Improper Input Validation via the fund function in fuels-ts/packages/account/src/account.ts file, that gets the needed resources statelessly with the function getResourcesToSpend without taking into consideration already used UTXOs. This vulnerability will lead to unexpected SDK behaviourthat could cause a transaction to not get included in the txpool/in a block or for a previous transaction to silently get removed from the txpool and be replaced with a new one.

    How to fix Improper Input Validation?

    Upgrade fuels to version 0.93.0 or higher.

    <0.93.0