defunctzombie / node-url

node.js core url module as a module
MIT License
375 stars 96 forks source link

potential security vulnerability #68

Closed ranjit-git closed 9 months ago

ranjit-git commented 9 months ago

Hi, I found a potential security vulnerability in node-url . You can read the report by going report url https://www.huntr.dev/bounties/d61053da-10a3-4298-8ab7-8d9155af2f9c/ . This report is currently private and only maintainer can see the report . I have submiited this report through open-source bugbounty platform https://www.huntr.dev/. Fix this ASAP . Plz let me know if you are unable to view the report ?

ljharb commented 9 months ago

There’s no need for the issue; i got the email from hunter.dev for your previous reports and received one for this too. I’ll respond there.

ljharb commented 9 months ago

Actually i didn’t get this email notification, which is odd; cc @adam-nygate (also the 418sec website is down)

adam-nygate commented 9 months ago

Not sure what happened with the email notification, we've got all green lights on our end.

Thanks for the note on the website @ljharb, fixed :)

ljharb commented 9 months ago

As discussed on the bounty, this package must match node; i can’t fix what node won’t. We can discuss further there.