2.1.1
4 years ago
1 months ago
Known vulnerabilities in the cryptoadvance.specter package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
cryptoadvance.specter is an A GUI for Bitcoin Core & Electrum optimised to work with airgapped hardware wallets Affected versions of this package are vulnerable to Open Redirect where the "next" parameter during the login process on Specter desktop can be manipulated to redirect users to an unauthorized domain after login. This vulnerability poses a phishing risk, as attackers can easily direct users to malicious sites by altering the "next" parameter in the URL. How to fix Open Redirect? Upgrade | [,2.0.2) |