Vulnerabilities

1 via 1 paths

Dependencies

126

Source

GitHub

Commit

fb5f10da

Find, fix and prevent vulnerabilities in your code.

Severity
  • 1
Status
  • 1
  • 0
  • 0

medium severity

Improper Neutralization

  • Vulnerable module: @auth/core
  • Introduced through: next-auth@5.0.0-beta.30

Detailed paths

  • Introduced through: carineland@ujju16/carineland#fb5f10dae813a5f00d8864a97c84f93d95bd478f next-auth@5.0.0-beta.30 @auth/core@0.41.0

Overview

@auth/core is an Authentication for the Web.

Affected versions of this package are vulnerable to Improper Neutralization in the email validation component. An attacker can intercept sensitive authentication emails by submitting a specially crafted email address that manipulates the parsing logic, causing messages to be sent to an unintended mailbox.

Remediation

Upgrade @auth/core to version 0.41.1 or higher.

References