-
-
Notifications
You must be signed in to change notification settings - Fork 130
Open
Description
Improper Input Validation
Medium severity
-
Package Manager: npm
-
Vulnerable module: nanoid
-
Introduced through: reactjs-tiptap-editor@0.3.11
-
Detailed paths
Introduced through: reactjs-tiptap-editor@0.3.11 › @excalidraw/excalidraw@0.18.0 › @excalidraw/mermaid-to-excalidraw@1.1.2 › nanoid@4.0.2
Introduced through: reactjs-tiptap-editor@0.3.11 › @excalidraw/excalidraw@0.18.0 › nanoid@3.3.3 -
Overview
Affected versions of this package are vulnerable to Improper Input Validation due to the mishandling of fractional values in the nanoid function. By exploiting this vulnerability, an attacker can achieve an infinite loop. -
Remediation
Upgrade nanoid to version 3.3.8, 5.0.9 or higher. -
References
GitHub Commit
GitHub PR
GitHub Release
hunghg255
Metadata
Metadata
Assignees
Labels
No labels