Johannschopplich maintains the Nuxt API Party library, a focused integration tool for API consumption within the Nuxt framework ecosystem. Its observed vulnerability landscape centers on resource-handling and input-validation weaknesses including out-of-bounds writes, server-side request forgery, uncontrolled recursion, and uncontrolled resource consumption, reflecting the attack surface inherent to a library that mediates external API requests. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Johannschopplich over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-49800HIGH `nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no filter on which options are avai | Dec 9, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-49799HIGH `nuxt-api-party` is an open source module to proxy API requests. nuxt-api-party attempts to check if the user has passed an absolute URL to prevent the aforementioned attack. This | Dec 9, 2023 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Johannschopplich.
Media articles that mention a CVE ID that affects a product developed by Johannschopplich — matched by CVE ID, not by vendor name.