pym.js@0.4.5 vulnerabilities

Resize an iframe responsively depending on the height of its content and the width of its container.

Direct Vulnerabilities

Known vulnerabilities in the pym.js package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Cross-site Request Forgery (CSRF)

pym.js embeds and resizes an iframe responsively (width and height) within its parent container.

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the _onNavigateToMessage function. This attack appear to be exploitable via Attacker gains full javascript access to pages with Pym.js embeds when user visits an attacker crafted page.

How to fix Cross-site Request Forgery (CSRF)?

Upgrade pym.js to version 1.3.2 or higher.

<1.3.2
  • H
Cross-site Request Forgery (CSRF)

pym.js embeds and resizes an iframe responsively (width and height) within its parent container.

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the _onNavigateToMessage function. This attack appear to be exploitable via Attacker gains full javascript access to pages with Pym.js embeds when user visits an attacker crafted page.

How to fix Cross-site Request Forgery (CSRF)?

Upgrade pym.js to version 1.3.2 or higher.

<1.3.2