-
Notifications
You must be signed in to change notification settings - Fork 1.4k
Vulnerability in Cap project #1715
Copy link
Copy link
Open
Labels
bugSomething isn't workingSomething isn't working
Description
While working on Cap project, I scanned the dependency manifest and found that it uses a vulnerable version of @nestjs/core. The scan revealed an injection issue in Server-Sent Events handling, where unsanitized type and id fields can allow attackers to inject arbitrary events or manipulate SSE streams, potentially leading to spoofing or data injection.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working