Intel

AIKIDO-2026-10074

lob is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

65

Medium Risk

This Affects:

JSlob
1.0.0 - 7.0.1
Fixed in 7.1.0

TL;DR

Affected versions of this package are vulnerable to a high-severity path traversal issue in the _transmit function in resourceBase.js, because the uri parameter is not properly sanitized and could be manipulated to access unintended API endpoints. This patch also replaces the deprecated request package with axios to resolve a security vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

lob is vulnerable to Path Traversal in versions 1.0.0 - 7.0.1.

How to fix this

Upgrade the lob library to the patch version.