Intel

AIKIDO-2025-10294

svix is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

17

Low Risk

This Affects:

JAVAsvix
0.61.0 - 1.64.1
Fixed in 1.65.0

TL;DR

Affected versions of the package do not properly sanitize URLs configured for operational server webhooks. The SVIX_OPERATIONAL_WEBHOOK_ADDRESS value is used without validation or sanitization, allowing potentially unsafe or malformed URLs to be added and used by the server.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

svix is vulnerable to Improper Input Validation in versions 0.61.0 - 1.64.1.

How to fix this

Upgrade the com.svix:svix library to the patch version.