@metamask/assets-controllers is vulnerable to Client-Side Injection Attacks
20
Low Risk
Affected versions of this package are vulnerable to phishing and malicious NFT metadata exploits due to insufficient URL validation in the UI layer, allowing attackers to bypass frontend checks and inject harmful links into NFT metadata. An attacker could craft malicious NFTs with embedded unsafe URLs that execute scripts, redirect to phishing sites, or trigger unwanted actions when rendered.
You are affected if you are using a version that falls within the vulnerable range.
@metamask/assets-controllers is vulnerable to Client-Side Injection Attacks in versions 33.0.0 - 65.0.0.
Upgrade the @metamask/assets-controllers library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant