Skip to content

Pensar - Upgrade firebase from 9.23.0 to 10.9.0#1

Open
pensarapp[bot] wants to merge 1 commit intomainfrom
pensar-auto-fix-C3RQ
Open

Pensar - Upgrade firebase from 9.23.0 to 10.9.0#1
pensarapp[bot] wants to merge 1 commit intomainfrom
pensar-auto-fix-C3RQ

Conversation

@pensarapp
Copy link
Copy Markdown

@pensarapp pensarapp bot commented Oct 16, 2025

Secured with Pensar

Upgrading firebase from 9.23.0 to 10.9.0

Fixes Summary

File Fix Explanation
 /nextjs/package.json 
The upgrade to version 10.9.0 fixes the vulnerability by ensuring that the SDK properly handles the _authTokenSyncURL field, preventing attackers from manipulating it to redirect authentication tokens. This update addresses the issues identified under CWE-79 without requiring a major version change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants