garycourt / uri-js

An RFC 3986 compliant, scheme extendable URI parsing/validating/normalizing/resolving library for JavaScript
Other
304 stars 69 forks source link

potential security vulnerability #92

Open ranjit-git opened 10 months ago

ranjit-git commented 10 months ago

a high severity securty vulnerability has been itentified for this npm library . Report as been submitted about 7 months ago but still no update You can check report bellow https://www.huntr.dev/bounties/90e7449a-7c06-44b5-a837-1be5fb36c16e/

ranjit-git commented 9 months ago

any update about this vulnerability?

kibertoad commented 5 months ago

I've created a fork of the project with the aim to address all known issues with uri-js: https://github.com/kibertoad/toad-uri-js

Would you be open to contribute a fix for this security vulnerability?

andreinwald commented 2 months ago

97 - replacement for this library