Loading HuntDB...

GHSA-rhvc-x32h-5526

GitHub Security Advisory

No CSRF Validation in droppy

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Affected versions of `droppy` are vulnerable to cross-site socket forgery. The package does not perform verification for cross-domain websocket requests, and as a result, an attacker can create a web page that opens up a websocket connection on behalf of the user visiting the page. The attacker can then perform any action that the target user could, including adding a new admin account under their control, or deleting others.

## Recommendation

Update to version 3.5.0 or later.

Affected Packages

npm droppy
Affected versions: 0 (fixed in 3.5.0)

Related CVEs

Key Information

GHSA ID
GHSA-rhvc-x32h-5526
Published
February 18, 2019 11:39 PM
Last Modified
August 31, 2020 6:10 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
droppy
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 3, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.