tesseract.js@1.0.11 vulnerabilities

Pure Javascript Multilingual OCR

Direct Vulnerabilities

Known vulnerabilities in the tesseract.js package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Insecure Default Configuration

tesseract.js is a javascript library that gets words in almost any language out of images.

Affected versions of this package are vulnerable to Insecure Default Configuration and may lead to instability and privacy violations. Requests may be proxied through crossorigin.me which clearly states is not suitable for production use.

How to fix Insecure Default Configuration?

Upgrade tesseract.js to version 1.0.19 or higher.

<1.0.19