Vulnerabilities

1 via 2 paths

Dependencies

134

Source

GitHub

Find, fix and prevent vulnerabilities in your code.

Issue type
  • 1
  • 1
Severity
  • 2
Status
  • 2
  • 0
  • 0

medium severity
new

Cross-site Request Forgery (CSRF)

  • Vulnerable module: react-router
  • Introduced through: react-router@7.18.2 and react-router-dom@7.18.2

Detailed paths

  • Introduced through: appersonautomotive.com@webjamapps/AppersonAuto react-router@7.18.2
    Remediation: Upgrade to react-router@8.3.0.
  • Introduced through: appersonautomotive.com@webjamapps/AppersonAuto react-router-dom@7.18.2 react-router@7.18.2

Overview

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the unstable RSC APIs. An attacker can execute unauthorized actions by tricking a user into submitting crafted requests.

Note: This is only exploitable if the unstable RSC APIs are enabled in the application.

Remediation

Upgrade react-router to version 8.3.0 or higher.

References

medium severity

MPL-2.0 license

  • Module: lightningcss
  • Introduced through: vite@8.1.5

Detailed paths

  • Introduced through: appersonautomotive.com@webjamapps/AppersonAuto vite@8.1.5 lightningcss@1.33.0

MPL-2.0 license