@apidevtools/json-schema-ref-parser is vulnerable to Server-Side Request Forgery
20
Low Risk
Affected versions of this package are vulnerable to Server-Side Request Forgery (SSRF) due to the default schema resolver can potentially fetch requests from tainted urls without further validation. An attacker could exploit this by submitting a malicious schema with $ref pointing to localhost, internal APIs, or cloud metadata services, potentially bypassing network controls and accessing sensitive data.
You are affected if you are using a version that falls within the vulnerable range.
@apidevtools/json-schema-ref-parser is vulnerable to Server-Side Request Forgery in versions 11.4.1 - 13.0.5.
Upgrade the @apidevtools/json-schema-ref-parser library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant