CVE-2025-64166 | mercurius-js mercurius up to 16.3.x Content-Type Header fetch cross-site request forgery (GHSA-v66j-6wwf-jc57)
A vulnerability labeled as problematic has been found in mercurius-js mercurius up to 16.3.x. The affected element is the function fetch of the component Content-Type Header Handler. The manipulation of the argument Content-Type results in cross-site request forgery.
This vulnerability is reported as CVE-2025-64166. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.