@atomicfi/transact-javascript is vulnerable to Improper Input Validation
48
Medium Risk
Affected versions of this package allowed unvalidated user-controlled URLs to be passed directly to window.open, enabling arbitrary schemes such as javascript: or data: to be executed in a new browser context. This could allow an attacker to craft a malicious payload.url that executes JavaScript or redirects users to phishing pages when the link is opened. By injecting a specially crafted URL into the event handler, an attacker could trigger client-side script execution or malicious navigation. The patch mitigates this by parsing the URL and restricting navigation strictly to the https: protocol.
You are affected if you are using a version that falls within the vulnerable range.
@atomicfi/transact-javascript is vulnerable to Improper Input Validation in versions 3.0.10 - 3.0.10.
Upgrade the @atomicfi/transact-javascript library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant