cloudinary is vulnerable to Improper Neutralization of Parameter/Argument Delimiters
85
High Risk
Affected versions of this package are vulnerable to parameter injection in the api_sign_request function. The flaw occurs because ampersands (&) in parameter values are not properly handled, allowing attackers to inject additional parameters and potentially alter request behavior.
You are affected if you are using a version that falls within the vulnerable range.
cloudinary is vulnerable to Improper Neutralization of Parameter/Argument Delimiters in versions 1.0.0 - 2.6.1.
Upgrade the cloudinary library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant