elysia is vulnerable to Improper Control of Generation of Code ('Code Injection')
85
High Risk
Affected versions of this package are vulnerable to Arbitrary Code Execution due to improper sanitization of user input when dynamically generating code for cookie signing. The vulnerability exists because the cookie.secrets configuration is directly embedded into generated function code using string concatenation without proper escaping, allowing an attacker who can control this value to inject arbitrary JavaScript code.
You are affected if you are using a version that falls within the vulnerable range.
elysia is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.7.0 - 1.4.16.
Upgrade the elysia library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant