uppy is vulnerable to Overly Permissive Cross-domain Whitelist
30
Low Risk
Affected versions of the package are vulnerable to overly permissive cross-domain whitelisting. When the corsOrigins environment variable is set to *, it allows requests from any origin, bypassing intended security restrictions and exposing the application to potential Cross-site Request Forgery (CSRF) or data theft attacks.
You are affected if you are using a version that falls within the vulnerable range.
uppy is vulnerable to Overly Permissive Cross-domain Whitelist in versions 3.5.0 - 4.5.0.
Upgrade the uppy library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant