Vulnerability CVE-2022-0686


Published: 2022-02-20

Description:
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

Type:

CWE-639

(Authorization Bypass Through User-Controlled Key)

 References:
https://huntr.dev/bounties/55fd06cd-9054-4d80-83be-eb5a454be78c
https://github.com/unshiftio/url-parse/commit/d5c64791ef496ca5459ae7f2176a31ea53b127e5

Copyright 2026, cxsecurity.com

 

Back to Top