@vtex/api is vulnerable to Weak Authentication
80
High Risk
Affected versions of the package are vulnerable to weak authentication, allowing cross-account requests. The vulnerability occurs because the system permits such requests as long as the target account contains a user identified by the token, regardless of whether the user is authorized to access that account. This flaw could enable unauthorized access or data exposure between accounts.
You are affected if you are using a version that falls within the vulnerable range.
@vtex/api is vulnerable to Weak Authentication in versions 3.0.0 - 6.47.0.
Upgrade the @vtex/api library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant