@vendure/ui-devkit is vulnerable to Exposure of Sensitive Information
40
Medium Risk
Affected versions of the package may expose sensitive information. A custom field with internal: true and public: false is accessible via the Shop API, potentially allowing unauthorized access to sensitive data.
You are affected if you are using a version that falls within the vulnerable range.
@vendure/ui-devkit is vulnerable to Exposure of Sensitive Information in versions 1.0.0 - 3.0.1.
Upgrade the @vendure/ui-devkit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant