CVE-2021-27516: Improper Neutralization
(updated )
URI.js (aka urijs) mishandles certain uses of backslash such as http:\/
and interprets the URI as a relative path.
References
Detect and mitigate CVE-2021-27516 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →