uppy is vulnerable to Cross-Site Request Forgery (CSRF)
30
Low Risk
Affected versions of the package do not provide explicit protection against Cross-site Request Forgery (CSRF) attacks in the OAuth2 grant configuration. This vulnerability allows an attacker to potentially manipulate the authorization process by tricking a user into making unintended requests, compromising the security of the application.
You are affected if you are using a version that falls within the vulnerable range.
uppy is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.27.0 - 4.6.0.
Upgrade the uppy library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant