PushwooshXCFramework is vulnerable to Improper Input Validation
40
Medium Risk
Affected versions of this package allowed the set_base_url remote command to accept arbitrary URL schemes without proper validation, enabling unsafe protocol handling. An attacker could supply a crafted URL using non-HTTP(S) schemes (e.g., file://, ftp://, or custom handlers) to coerce the application into accessing local resources, internal services, or unexpected endpoints. This may lead to local file disclosure, SSRF-like behavior, or abuse of protocol handlers depending on how the base URL is consumed. The issue is mitigated by restricting accepted schemes to http:// and https:// only.
You are affected if you are using a version that falls within the vulnerable range.
PushwooshXCFramework is vulnerable to Improper Input Validation in versions 7.0.0 - 7.0.20.
Upgrade the PushwooshXCFramework library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant