plasmo icon indicating copy to clipboard operation
plasmo copied to clipboard

[BUG] High Security Issue: msgpackr's Conversion of Property Names to Strings Can Trigger Infinite Recursion

Open velineurce opened this issue 7 months ago • 0 comments

What happened?

Hey Plasmo team.

I've tried to contact you via [email protected] but the email seems to not work.

We've identified a high-security issue in your repository related to msgpackr. The vulnerability arises from msgpackr's conversion of property names to strings, which can trigger infinite recursion.

Details:

Severity: High (8.6/10) Affected Version: [email protected] Fixed Version: 1.10.1 Conflicting Dependency: [email protected] requires [email protected] via [email protected] Dependabot is unable to update msgpackr to a non-vulnerable version due to this dependency conflict.

CVSS Base Metrics:

Attack Vector: Network Attack Complexity: Low Privileges Required: None User Interaction: None Scope: Changed Confidentiality: None Integrity: None Please consider updating the dependencies to address this issue.

Thanks!

Version

Latest

What OS are you seeing the problem on?

No response

What browsers are you seeing the problem on?

No response

Relevant log output

No response

(OPTIONAL) Contribution

  • n/a I would like to fix this BUG via a PR

Code of Conduct

  • [X] I agree to follow this project's Code of Conduct
  • [X] I checked the current issues for duplicate problems.

velineurce avatar Jul 31 '24 01:07 velineurce