react-devtools-core@2.5.2 vulnerabilities

Use react-devtools outside of the browser

Direct Vulnerabilities

Known vulnerabilities in the react-devtools-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Improper Authorization

react-devtools-core is an Use react-devtools outside of the browser

Affected versions of this package are vulnerable to Improper Authorization through the window.addEventListener('message', <listener>) function. By exploiting this vulnerability, an attacker can generate clicks and revenue or initiate a Distributed Denial of Service (DDoS) attack without the victims’ knowledge or consent by sending a message that triggers a fetch request to an arbitrary

How to fix Improper Authorization?

Upgrade react-devtools-core to version 4.28.4 or higher.

<4.28.4