npm package @bananacool467/ui-tools patched for unauthenticated terminal flaw
A security vulnerability has been disclosed in the npm package @bananacool467/ui-tools, affecting versions 0.1.0-beta through 0.1.7-beta. These versions exposed an unauthenticated WebSocket terminal endpoint, potentially allowing anyone with network access to interact with a server-side shell session. The flaw is tracked under OSV advisory MAL-2026-13416, identified through findings by Amazon Inspector. The maintainer addressed the issue in version 0.1.9-beta by adding token-based authentication before the WebSocket upgrade is accepted. Users running any affected version are advised to upgrade immediately using npm install @bananacool467/ui-tools@0.1.9-beta or later.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in