npm Package Vulnerabilities
Vulnerabilities associated with urijs.
Packages
Clear package- openclaw588 vulnerabilities
- n8n139 vulnerabilities
- parse-server116 vulnerabilities
- flowise112 vulnerabilities
- electron65 vulnerabilities
- next64 vulnerabilities
- directus58 vulnerabilities
- nocodb54 vulnerabilities
- hono47 vulnerabilities
- axios43 vulnerabilities
- vm243 vulnerabilities
- ghost41 vulnerabilities
- @budibase/server40 vulnerabilities
- undici35 vulnerabilities
- flowise-components29 vulnerabilities
- @anthropic-ai/claude-code28 vulnerabilities
- dompurify28 vulnerabilities
- pnpm28 vulnerabilities
- astro25 vulnerabilities
- @openzeppelin/contracts-upgradeable22 vulnerabilities
- better-auth22 vulnerabilities
- vite22 vulnerabilities
- @openzeppelin/contracts21 vulnerabilities
- fuxa-server21 vulnerabilities
- nuxt21 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-1243MEDIUM | CRHTLF can lead to invalid protocol extraction potentially leading to XSS in medialize/uri.jsCRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11. CWE-20Apr 5, 2022 | CVSS6.1v3.1 | EPSS0.663% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1233MEDIUM | URL Confusion When Scheme Not Supplied in medialize/uri.jsURL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11. | CVSS6.1v3.1 | EPSS0.787% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0868MEDIUM | Open Redirect in medialize/uri.jsOpen Redirect in GitHub repository medialize/uri.js prior to 1.19.10. CWE-601Mar 6, 2022 | CVSS6.1v3.1 | EPSS0.719% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-24723MEDIUM | Improper Input Validation in URI.jsURI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround. CWE-20Mar 3, 2022 | CVSS5.3v3.1 | EPSS1.99% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0613MEDIUM | Authorization Bypass Through User-Controlled Key in medialize/uri.jsAuthorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8. CWE-639Feb 16, 2022 | CVSS6.5v3.1 | EPSS1.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-3647MEDIUM | Open Redirect in medialize/URI.jsURI.js is vulnerable to URL Redirection to Untrusted Site CWE-601Jul 16, 2021 | CVSS6.1v3.1 | EPSS0.91% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-27516HIGH | URIjs Hostname spoofing via backslashes in URLURI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. CWE-20Feb 21, 2021 | CVSS7.5v3.1 | EPSS2.48% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-26291MEDIUM | Hostname spoofing in URI.jsURI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at (`@`) character. If the hostname is used in security decisions, the decision may be incorrect. Depending on library usage and attacker intent, impacts may include allow/block list bypasses, SSRF attacks, open redirects, or other undesired behavior. For example the URL `https://expected-example.com\@observed-example.co… CWE-20Dec 30, 2020 | CVSS6.5v3.1 | EPSS1.69% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |