codex is vulnerable to Broken Access Control
46
Medium Risk
Affected versions of this package contain an access control bypass vulnerability that allows users to view comics in included groups they are not part of, due to inadequate permission checks during content retrieval. An attacker could exploit this by manipulating request parameters, such as comic or group IDs, to access restricted comics without proper authorization, leading to unauthorized disclosure of sensitive content.
You are affected if you are using a version that falls within the vulnerable range and if you are running the package in a UNIX environment.
codex is vulnerable to Broken Access Control in versions 1.0.0 - 1.9.8.
Upgrade the codex library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant