Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVwMjgtNjNtYy1jZ3I5
Cross-Site Scripting bypass in html-purify
All versions of html-purify are vulnerable to cross-site scripting. The data attribute inside of object tags is not properly sanitized and allows javascript URIs leading to code execution.
No fix is currently available. Consider using an alternative package until a fix is made available.
Permalink: https://github.com/advisories/GHSA-5p28-63mc-cgr9JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVwMjgtNjNtYy1jZ3I5
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 4 years ago
Updated: over 1 year ago
Identifiers: GHSA-5p28-63mc-cgr9
References: Blast Radius: 0.0
Affected Packages
npm:html-purify
Dependent packages: 3Dependent repositories: 8
Downloads: 325 last month
Affected Version Ranges: <= 1.1.0
No known fixed version
All affected versions: 1.0.1, 1.1.0