@lightsparkdev/lightspark-sdk is vulnerable to Observable Timing Discrepancy
20
Low Risk
Affected versions of this package are vulnerable to a timing attack in webhook signature verification due to the use of a non-constant-time string comparison function. This vulnerability allows an attacker to exploit the timing differences in the verification process by sending numerous webhook requests with incremental signature changes and measuring the response times. Through statistical analysis, the attacker can gradually deduce the correct signature, potentially leading to unauthorized webhook execution or secret leakage.
You are affected if you are using a version that falls within the vulnerable range.
@lightsparkdev/lightspark-sdk is vulnerable to Observable Timing Discrepancy in versions 1.0.6 - 1.9.11.
Upgrade the @lightsparkdev/lightspark-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant