Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVwMjgtNjNtYy1jZ3I5

Cross-Site Scripting bypass in html-purify

All versions of html-purify are vulnerable to cross-site scripting. The data attribute inside of object tags is not properly sanitized and allows javascript URIs leading to code execution.

No fix is currently available. Consider using an alternative package until a fix is made available.

Permalink: https://github.com/advisories/GHSA-5p28-63mc-cgr9
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVwMjgtNjNtYy1jZ3I5
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 4 years ago
Updated: over 1 year ago


Identifiers: GHSA-5p28-63mc-cgr9
References: Blast Radius: 0.0

Affected Packages

npm:html-purify
Dependent packages: 3
Dependent repositories: 8
Downloads: 325 last month
Affected Version Ranges: <= 1.1.0
No known fixed version
All affected versions: 1.0.1, 1.1.0