5.0.300
9 years ago
5 months ago
Known vulnerabilities in the scratch-vm package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
scratch-vm is a Virtual Machine for Scratch 3.0 Affected versions of this package are vulnerable to Improper Input Validation. When loading an SB3, it is determined whether a block is part of an extension by inspecting its "extended" opcode (for example, How to fix Improper Input Validation? Upgrade | >=0.1.0-prerelease.1524239808 <0.2.0-prerelease.20200714185213 |