PT-2026-95591 · Npm · Uri.Js
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
uri-js versions 4.4.1 and earlier
Description
An improper UTF-8 decoding issue exists in the
pctDecChars() function. This flaw allows the decoding of invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can use crafted percent-encoded payloads to bypass platform decoder validation, enabling the injection of path traversal or CRLF (Carriage Return Line Feed) sequences that may be processed without filtering by downstream consumers.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uri.Js