VYPR

npm package

jsen

pkg:npm/jsen

Vulnerabilities (1)

  • CVE-2020-7777Nov 23, 2020
    affected <= 0.6.6

    This affects all versions of package jsen. If an attacker can control the schema file, it could run arbitrary JavaScript code on the victim machine. In the module description and README file there is no mention about the risks of untrusted schema files, so I assume that this is a