uppy is vulnerable to Overly Permissive Cross-domain Whitelist
30
Low Risk
Affected versions of the package are vulnerable to overly permissive cross-domain whitelisting. When the corsOrigins environment variable is set to *, it allows requests from any origin, bypassing intended security restrictions and exposing the application to potential Cross-site Request Forgery (CSRF) or data theft attacks.
You are affected if you are using a version that falls within the vulnerable range.
uppy is vulnerable to Overly Permissive Cross-domain Whitelist in versions 3.5.0 - 4.5.0.
Upgrade the uppy library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant