GHSA-84fv-prrc-5ggr
GitHub Security Advisory
Route Validation Bypass in call
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Affected versions of `call` do not validate empty parameters, which may result in a bypass of route validation rules.
## Proof of Concept
Routing Scheme:
```
/api/{param}/{param2}/details
```
Triggering Request Path:
```
/api///
```
## Recommendation
Update to version 3.0.2 or later.
Affected Packages
npm
call
Affected versions:
2.0.1
(fixed in 3.0.2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.