6.0.3
11 years ago
6 years ago
Known vulnerabilities in the kind-of package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
kind-of is a package that gets the native type of a value. Affected versions of this package are vulnerable to Validation Bypass. It leverages the built-in constructor of unsafe user-input to detect type information. However, a crafted payload can overwrite this built in attribute to manipulate the type detection result. How to fix Validation Bypass? Upgrade | >=6.0.0 <6.0.3 |