@liveblocks/react-ui is vulnerable to Missing Authorization
10
Low Risk
Affected versions of this package fail to disable or hide UI actions properly (e.g., adding comments, resolving/unresolving threads) for users without the necessary permissions. An attacker can exploit this issue by interacting with seemingly available actions despite lacking proper authorization, potentially leading to manipulating thread states or adding reactions, disrupting discussions, and misusing privileged functions.
You are affected if you are using a version that falls within the vulnerable range.
@liveblocks/react-ui is vulnerable to Missing Authorization in versions 2.0.0 - 2.24.1.
Upgrade the @liveblocks/react-ui library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant