fast-uri is vulnerable to Path Traversal
75
High Risk
normalize() and equal() decoded percent-encoded slash and dot segments before dot-segment removal, so encoded sequences could collapse paths the same way literal separators would. Distinct URIs could normalize to the same path and compare equal, weakening checks that rely on normalization or equality over attacker-controlled URLs. The fix preserves reserved percent-escapes in path handling so policy based on normalized paths cannot be bypassed that way.
You are affected if you are using a version that falls within the vulnerable range.
fast-uri is vulnerable to Path Traversal in versions 0.0.1 - 3.1.0.
Upgrade the fast-uri library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant