@settlemint/asset-tokenization-kit is vulnerable to Log Injection
29
Low Risk
Affected versions of this package are affected by improper input validation in error messages and user-controlled search strings, which can lead to injection attacks. Attackers can exploit this by injecting malicious input, such as special characters, into error logs or search queries. This issue could poison log files or manipulate application behavior, as mishandling backslashes in search queries regex sanitization may allow attackers to inject single quotes, potentially leading to SQL injection.
You are affected if you are using a version that falls within the vulnerable range.
@settlemint/asset-tokenization-kit is vulnerable to Log Injection in versions 0.0.10 - 0.1.15.
Upgrade the @settlemint/asset-tokenization-kit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant