garycourt / uri-js

An RFC 3986 compliant, scheme extendable URI parsing/validating/normalizing/resolving library for JavaScript
Other
305 stars 68 forks source link

potential security vulnerability #92

Open ranjit-git opened 1 year ago

ranjit-git commented 1 year ago

a high severity securty vulnerability has been itentified for this npm library . Report as been submitted about 7 months ago but still no update You can check report bellow https://www.huntr.dev/bounties/90e7449a-7c06-44b5-a837-1be5fb36c16e/

ranjit-git commented 1 year ago

any update about this vulnerability?

kibertoad commented 9 months ago

I've created a fork of the project with the aim to address all known issues with uri-js: https://github.com/kibertoad/toad-uri-js

Would you be open to contribute a fix for this security vulnerability?

andreinwald commented 6 months ago

97 - replacement for this library