react-devtools-core@3.6.3 vulnerabilities

Use react-devtools outside of the browser

Direct Vulnerabilities

Known vulnerabilities in the react-devtools-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Improper Authorization

react-devtools-core is an Use react-devtools outside of the browser

Affected versions of this package are vulnerable to Improper Authorization through the window.addEventListener('message', <listener>) function. By exploiting this vulnerability, an attacker can generate clicks and revenue or initiate a Distributed Denial of Service (DDoS) attack without the victims’ knowledge or consent by sending a message that triggers a fetch request to an arbitrary

How to fix Improper Authorization?

Upgrade react-devtools-core to version 4.28.4 or higher.