Skip to content
tesseract.jsGHSA-83rx-c8cr-6j8q

Insecure Default Configuration in tesseract.js

Medium5.9Published Jun 5, 2019 · updated Aug 4, 2021

Versions of `tesseract.js` prior to 1.0.19 default to using a third-party proxy. Requests may be proxied through `crossorigin.me` which clearly states is not suitable for production use. This may lead to instability and privacy violations. ## Recommendation Upgrade to version 1.0.19 or later.

GitHub advisory

Affected versions

PackageAffectedFixed in
tesseract.js
npm
< 1.0.191.0.19
Details and references

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.