@medusajs/medusa is vulnerable to Information Disclosure
51
Medium Risk
Affected versions of this package possess insecure handling of JWT tokens when running in server-side rendering (SSR) contexts. Specifically, when a guest user adds a product to their cart and enters shipping details, clicking Continue to delivery directly links the cart to the email of the last registered user. An attacker could exploit this vulnerability to gain unauthorized access to the data of registered users.
You are affected if you are using a version that falls within the vulnerable range.
@medusajs/medusa is vulnerable to Information Disclosure in versions 1.17.0 - 1.20.10.
Upgrade the @medusajs/medusa library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant