[GH-ISSUE #18] socket.io@2.4.1 has a security issue #7

Closed
opened 2026-05-23 08:38:10 -06:00 by gitea-mirror · 3 comments
Owner

Originally created by @andywillis on GitHub (May 13, 2022).
Original GitHub issue: https://github.com/appy-one/acebase-server/issues/18

Originally assigned to: @appy-one on GitHub.

acebase-server@1.10.0 requires engine.io@~3.5.0 via a transitive dependency on socket.io@2.4.1

The current version of socket.io is v4.5.0 which would probably fix it. YMMV tho.

Looking forward to using this for my new project. Good luck!

Originally created by @andywillis on GitHub (May 13, 2022). Original GitHub issue: https://github.com/appy-one/acebase-server/issues/18 Originally assigned to: @appy-one on GitHub. > acebase-server@1.10.0 requires engine.io@~3.5.0 via a transitive dependency on socket.io@2.4.1 The current version of socket.io is v4.5.0 which would probably fix it. YMMV tho. Looking forward to using this for my new project. Good luck!
Author
Owner

@appy-one commented on GitHub (May 13, 2022):

Thanks Andy, I'll investigate this

<!-- gh-comment-id:1125717636 --> @appy-one commented on GitHub (May 13, 2022): Thanks Andy, I'll investigate this
Author
Owner

@appy-one commented on GitHub (May 13, 2022):

I've updated socket.io to v4.5 in this commit. I've briefly tested if it works with current clients that still use 2.x, appears to work. Will do some more testing next week. If you'd like to test yourself in the mean time, please do!

<!-- gh-comment-id:1126185032 --> @appy-one commented on GitHub (May 13, 2022): I've updated socket.io to v4.5 in [this commit](https://github.com/appy-one/acebase-server/commit/bd5446873ba533a9c7ca9cd496ae5682b7dc3444). I've briefly tested if it works with current clients that still use 2.x, appears to work. Will do some more testing next week. If you'd like to test yourself in the mean time, please do!
Author
Owner

@appy-one commented on GitHub (Jun 6, 2022):

I published v1.11.0 last week, which now uses Socket.IO v4.5. I thoroughly tested with current clients, let me know if you run into unexpected behavior.

Spread the word contribute Sponsor AceBase

<!-- gh-comment-id:1147497223 --> @appy-one commented on GitHub (Jun 6, 2022): I published [v1.11.0](https://github.com/appy-one/acebase-server/releases/tag/v1.11.0) last week, which now uses Socket.IO v4.5. I thoroughly tested with current clients, let me know if you run into unexpected behavior. [![Spread the word](https://user-images.githubusercontent.com/26569719/169265089-3d593555-e1ad-4390-986b-877ac2c38a47.svg)](https://twitter.com/intent/tweet?button=&url=https://github.com/appy-one/acebase&text=I'm+using+@AcebaseRealtime+in+my+project+to+make+my+life+easier!&button=) [![contribute](https://user-images.githubusercontent.com/26569719/169265318-30c4c6a5-7c89-46a0-a7a2-ef433a8192f4.svg)](https://github.com/appy-one/acebase#contributing) [![Sponsor AceBase](https://user-images.githubusercontent.com/26569719/168233053-8e56b243-4140-40ab-9a30-4cb3cc149bfe.svg)](https://github.com/sponsors/appy-one)
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/acebase-server#7
No description provided.