transloadit/uppy

transloadit/uppy

Releases4.44K
Frequency19 hours 50 minutes
Last Release
Stars30.9K
The next open source file uploader for web browsers :dog:

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
9.8 CRITICAL

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

< 3.3.16.5 MEDIUM5 MEDIUM

Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.

< 2.3.39.8 CRITICAL7.5 HIGH

uppy is vulnerable to Server-Side Request Forgery (SSRF)

= 2.0.0, < 1.13.27.5 HIGH5 MEDIUM

The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.

< 1.9.39.8 CRITICAL7.5 HIGH

The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.