npm package report

Is fluture-node safe?

1 known vulnerability, worst severity LOW.

cvss
2.6

how bad it is if exploited, out of 10

epss
0.80%

chance of exploitation in the next 30 days

xyz score
1.1

CyberXYZ composite, out of 10

fig. 01 — GHSA-32x6-qvw6-mxj4, the advisory selected below

// advisories

GHSA-32x6-qvw6-mxj4

LOWCVE-2022-24719

Using followRedirects or followRedirectsWith with any of the redirection strategies built into fluture-node 4.0.0 or 4.0.1, paired with a request that includes confidential headers such as Authorization or Cookie, exposes you to a vulnerability where, if the destination server were to redirect the request to a server on a third-party domain, or the same domain over unencrypted HTTP, the headers wo

Affected
>= 4.0.0, < 4.0.2
Fixed in
4.0.2
Weakness
CWE-200
Published
2022-03-01
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 01:39 UTC. The most recent advisory here was published 2022-03-01. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is fluture-node safe? npm package security report | CyberXYZ