cometchat-react-calls
Warn
Audited by Snyk on Jul 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Ringing/session integration relies on CometChat/Calls SDK runtime events fed by the app’s logged-in chat/call system (e.g., 1:1 uses
CometChat.addCallListener, group usesCometChat.addMessageListener), which can surface outsider-authored text that was submitted by other users in those message/call channels without any “select specific item via search/fetch” gate.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata