Kylart / MalScraper

Scrape everything you can from MyAnimeList.net
MIT License
177 stars 49 forks source link

high vulnerability #61

Closed aikozijlemans closed 3 years ago

aikozijlemans commented 3 years ago

High Server-Side Request Forgery

Package axios

Patched in >=0.21.1

Dependency of mal-scraper

Path mal-scraper > axios

More info https://npmjs.com/advisories/1594

Yaroster commented 3 years ago

https://github.com/axios/axios/commit/c7329fefc890050edd51e40e469a154d0117fc55

Here's how to preven SSRF in axios.

Kylart commented 3 years ago

This is updated and deployed in v2.11.3