@nuxtjs/plausible is vulnerable to Insufficient Verification of Data Authenticity
65
Medium Risk
Affected versions of this package improperly trust or fail to sanitize cf-connecting-ip and x-real-ip headers, allowing client-controlled IP spoofing through proxy header sniffing. An attacker may inject crafted headers to impersonate arbitrary IP addresses, bypass IP-based access controls, rate limiting, logging, or security policies. This can enable unauthorized access, evade detection mechanisms, or manipulate audit trails if the application relies on these headers for client identity validation.
You are affected if you are using a version that falls within the vulnerable range.
@nuxtjs/plausible is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.0 - 3.0.0.
Upgrade the @nuxtjs/plausible library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant