statsig-node is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
45
Medium Risk
Affected versions of the package may expose private personal information to unauthorized actors by revealing private user properties in the ClientInitializeResponse.
You are affected if you are using a version that falls within the vulnerable range.
statsig-node is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor in versions 5.20.0 - 5.25.0.
Upgrade the statsig-node library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant