2.15.0
1 years ago
19 days ago
Known vulnerabilities in the webcrack package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
webcrack is a Deobfuscate, unminify and unpack bundled javascript Affected versions of this package are vulnerable to Improper Input Validation when parsing and saving a malicious bundle. An attacker can overwrite files on the host system when using the unpack bundles feature in conjunction with the saving feature by crafting malicious input that includes path traversal sequences, exploiting the failure of path normalization checks. Note: This vulnerability impacts Windows operation systems. How to fix Improper Input Validation? Upgrade | <2.14.1 |