schema-inspector
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting schema-inspectorpage 1 of 1
- CVE-2019-10781CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.6.92020-01-22
In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector.
- CVE-2021-21267HIGHCVSS 7.5EG 7.5✓ Fixed in 2.0.02021-03-19
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `a@0.0.…
Check whether schema-inspector is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for schema-inspector CVEs against the assets you own.
Start Free Scan →