4.8.1
14 years ago
1 years ago
Known vulnerabilities in the socket.io package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
socket.io is a node.js realtime framework server. Affected versions of this package are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default. How to fix Insecure Defaults? Upgrade | <2.4.0 |
How to fix Insecure Randomness? Upgrade | <0.9.7 |
You can read more about How to fix Cross-site Scripting (XSS)? Upgrade | <0.9.6 |