Loading HuntDB...

GHSA-gpw9-fwm8-7rx7

GitHub Security Advisory

DoS vulnerability for apps with sockets enabled

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact
In Sails apps <=v1.5.6, an attacker can send a virtual request that will cause the node process to crash.

### Patches
This behavior was fixed in Sails [v1.5.7](https://github.com/balderdashy/sails/releases/tag/v1.5.7)

### Workarounds
Disable the sockets hook and remove the `sails.io.js` client

### References
https://github.com/balderdashy/sails/pull/7287

Big thanks to @ThomasRinsma at [Codean](https://www.linkedin.com/company/codeanio/)!

Affected Packages

npm sails
Affected versions: 0 (fixed in 1.5.7)

Related CVEs

Key Information

GHSA ID
GHSA-gpw9-fwm8-7rx7
Published
July 27, 2023 5:13 PM
Last Modified
July 27, 2023 9:36 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
sails
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 30, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.