twitter-fetcher@16.0.3 vulnerabilities

Fetch your twitter posts without using the new Twitter 1.1 API. Pure JavaScript!

Direct Vulnerabilities

Known vulnerabilities in the twitter-fetcher package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Access Control Bypass

twitter-fetcher is a Fetch your twitter posts without using the new Twitter 1.1 API. Pure JavaScript!

Affected versions of this package are vulnerable to Access Control Bypass due to missing the rel=noopener attribute, via the js/twitterFetcher.js file of the Link Target Handler component.

How to fix Access Control Bypass?

Upgrade twitter-fetcher to version 18.0.0 or higher.

<18.0.0