@nestjs/core@7.6.18 vulnerabilities

Nest - modern, fast, powerful node.js web framework (@core)

Direct Vulnerabilities

Known vulnerabilities in the @nestjs/core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Information Exposure

@nestjs/core is a Nest - modern, fast, powerful node.js web framework (@core)

Affected versions of this package are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client cancels a request while it is streaming a StreamableFile, the stream wrapped by the StreamableFile will be kept open.

How to fix Information Exposure?

Upgrade @nestjs/core to version 9.0.5 or higher.

<9.0.5