webcrack@1.4.0 vulnerabilities

Deobfuscate, unminify and unpack bundled javascript

  • latest version

    2.15.0

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    19 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the webcrack package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Input Validation

    webcrack is a Deobfuscate, unminify and unpack bundled javascript

    Affected versions of this package are vulnerable to Improper Input Validation when parsing and saving a malicious bundle. An attacker can overwrite files on the host system when using the unpack bundles feature in conjunction with the saving feature by crafting malicious input that includes path traversal sequences, exploiting the failure of path normalization checks.

    Note: This vulnerability impacts Windows operation systems.

    How to fix Improper Input Validation?

    Upgrade webcrack to version 2.14.1 or higher.

    <2.14.1