mimarec / swagger-doc-viewer

Viewer documentation for a OpenAPI Specification (fka The Swagger Specification)
MIT License
6 stars 5 forks source link

Multiple vulnerabilities Found in Repository #9

Open Bruswei opened 9 months ago

Bruswei commented 9 months ago

Hello Team.

I hope you are doing well. I am reaching out to inform you of a critical security matter. After cloning the repository, I have identified several vulnerabilities across multiple dependencies. These issues range in severity.

Key Vulnerabilities identified:

Improper Input Validation [Critical Severity]:  introduced by socket.io@1.7.4 > socket.io-parser@2.3.1, fix by upgrade socket.io-parser to version 3.3.3, 3.4.2, 4.0.5, 4.2.1 or higher.

Upgrading these dependencies will not only resolve the current vulnerabilities but will also enhance the overall security posture of the project.