ariadne is vulnerable to Download of Code Without Integrity Check
28
Low Risk
Affected versions of this package do not enforce integrity verification for externally loaded resources, allowing scripts to be executed without validating their authenticity. This may enable an attacker to tamper with third-party resources (e.g., via CDN compromise or man-in-the-middle attacks), resulting in the execution of malicious code in the application context. The issue is mitigated by introducing Subresource Integrity (SRI), ensuring that external resources are verified against a known cryptographic hash before execution.
You are affected if you are using a version that falls within the vulnerable range.
ariadne is vulnerable to Download of Code Without Integrity Check in versions 0.17.0 - 0.29.0.
Upgrade the ariadne library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant