CRITICAL 9.8 npm

Code Injection in morgan

GHSA-gwg9-rgvj-4h5j · CVE-2019-5413

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Verisons of morgan before 1.9.1 are vulnerable to code injection when user input is allowed into the filter or combined with a prototype pollution attack.

Recommendation

Update to version 1.9.1 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes