Skip to content

Issues Reported On Synk For This Package and It's Dependencies #268

@mr-burhanuddin

Description

@mr-burhanuddin

Improper Input Validation

Medium severity

  • Package Manager: npm

  • Vulnerable module: nanoid

  • Introduced through: reactjs-tiptap-editor@0.3.11

  • Detailed paths
    Introduced through: reactjs-tiptap-editor@0.3.11 › @excalidraw/excalidraw@0.18.0 › @excalidraw/mermaid-to-excalidraw@1.1.2 › nanoid@4.0.2
    Introduced through: reactjs-tiptap-editor@0.3.11 › @excalidraw/excalidraw@0.18.0 › nanoid@3.3.3

  • Overview
    Affected versions of this package are vulnerable to Improper Input Validation due to the mishandling of fractional values in the nanoid function. By exploiting this vulnerability, an attacker can achieve an infinite loop.

  • Remediation
    Upgrade nanoid to version 3.3.8, 5.0.9 or higher.

  • References
    GitHub Commit
    GitHub PR
    GitHub Release

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions