Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1oM3ZxLXd2OGotMzZnd80hOQ

Cross-site Scripting in Scratch-Svg-Renderer

A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted sb3 file.

Permalink: https://github.com/advisories/GHSA-h3vq-wv8j-36gw
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oM3ZxLXd2OGotMzZnd80hOQ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 2 years ago
Updated: about 1 year ago


Identifiers: GHSA-h3vq-wv8j-36gw, CVE-2020-27428
References: Repository: https://github.com/LLK/scratch-svg-renderer
Blast Radius: 0.0

Affected Packages

npm:scratch-svg-renderer
Dependent packages: 98
Dependent repositories: 264
Downloads: 11,839 last month
Affected Version Ranges: <= 0.2.0
No known fixed version
All affected versions: 0.1.0, 0.2.0