Skip to content

Bump typesense-js (CVE-2023-45857) #18

@JasonWhall

Description

@JasonWhall

Description

CSRF vulnerability affecting axios versions < 1.6.0.

typesense-docsearch-react depends on "typesense": "^1.7.2" which includes a vulnerable version of axios.

Steps to reproduce

Related bug

Expected behavior

Update typesense-js to >=1.8.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions