Origin Validation Error Affecting github.com/evanw/esbuild/pkg/api package, versions <0.25.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMEVANWESBUILDPKGAPI-8715699
  • published12 Feb 2025
  • disclosed10 Feb 2025
  • creditsapphi-red

Introduced: 10 Feb 2025

New CVE NOT AVAILABLE CWE-346  (opens in a new tab)

How to fix?

Upgrade github.com/evanw/esbuild/pkg/api to version 0.25.0 or higher.

Overview

Affected versions of this package are vulnerable to Origin Validation Error due to the default CORS settings that set the Access-Control-Allow-Origin: * header. An attacker can intercept and read potentially sensitive information by sending crafted requests from any origin.

Note:

This is only exploitable if the attacker knows the URL of the bundle output file name and if the victim has the source map option enabled.

References

CVSS Scores

version 4.0
version 3.1