inngest is vulnerable to Path Traversal
55
Medium Risk
Affected versions of this package constructed API client URLs without wrapping runId (and similar path segments) in encodeURIComponent, allowing attackers to inject reserved characters (such as /, .., or ?) into these segments. This could lead to unintended routing or path traversal-like effects.
You are affected if you are using a version that falls within the vulnerable range.
inngest is vulnerable to Path Traversal in versions 0.0.1 - 4.2.4.
Upgrade the inngest library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant