VYPR

npm package

@isomorphic-git/cors-proxy

pkg:npm/%40isomorphic-git/cors-proxy

Vulnerabilities (1)

  • CVE-2021-23664HigJan 21, 2022
    affected < 2.7.1fixed 2.7.1

    The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.