scratch-vm@0.1.0-prerelease.1501867154-prerelease.1501867168 vulnerabilities

Virtual Machine for Scratch 3.0

Direct Vulnerabilities

Known vulnerabilities in the scratch-vm package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Improper Input Validation

scratch-vm is a Virtual Machine for Scratch 3.0

Affected versions of this package are vulnerable to Improper Input Validation. When loading an SB3, it is determined whether a block is part of an extension by inspecting its "extended" opcode (for example, pen_clear requires the pen extension). The extension ID is not sanitised, and some characters may cause potential problems.

How to fix Improper Input Validation?

Upgrade scratch-vm to version 0.2.0-prerelease.20200714185213 or higher.

>=0.1.0-prerelease.1524239808 <0.2.0-prerelease.20200714185213