scratch-vm@0.1.0-prerelease.1517236563-prerelease.1517236578 vulnerabilities

Virtual Machine for Scratch 3.0

  • latest version

    5.0.39

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    18 hours ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the scratch-vm package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Improper Input Validation

    scratch-vm is a Virtual Machine for Scratch 3.0

    Affected versions of this package are vulnerable to Improper Input Validation. When loading an SB3, it is determined whether a block is part of an extension by inspecting its "extended" opcode (for example, pen_clear requires the pen extension). The extension ID is not sanitised, and some characters may cause potential problems.

    How to fix Improper Input Validation?

    Upgrade scratch-vm to version 0.2.0-prerelease.20200714185213 or higher.

    >=0.1.0-prerelease.1524239808 <0.2.0-prerelease.20200714185213