@stefanobartoletti/nuxt-social-share is vulnerable to Improper Input Validation
40
Medium Risk
Affected versions of this package are vulnerable to URL Injection due to improper input sanitization. The vulnerability occurs because user-supplied values from argTitle, argUser, argHashtags, and argImage are directly concatenated into the URL string before encoding occurs. An attacker can exploit this by injecting malicious parameters or altering the URL structure through these unencoded inputs, potentially leading to open redirects, phishing attacks, or other client-side vulnerabilities. The security risk exists because the initial concatenation happens before any encoding, allowing special characters to modify the final URL construction.
You are affected if you are using a version that falls within the vulnerable range.
@stefanobartoletti/nuxt-social-share is vulnerable to Improper Input Validation in versions 1.0.0 - 2.0.0.
Upgrade the @stefanobartoletti/nuxt-social-share library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant