In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @nestjs/core to version 11.1.18 or higher.
@nestjs/core is a Nest - modern, fast, powerful node.js web framework (@core)
Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the SseStream._transform function. An attacker can inject arbitrary Server-Sent Events, spoof event types, and corrupt reconnection state by supplying specially crafted newline characters in upstream data that is mapped to the type or id fields.
Note:
This is only exploitable if user-influenced data is mapped to these fields by developer code.