VDB
Sign up
MEDIUM6.1

GHSA-2fqv-h3r5-m4vf

Cross Site Scripting (XSS) in plotly.js

Quick fix

GHSA-2fqv-h3r5-m4vf — plotly.js: upgrade to the fixed version with the command below.

npm install plotly.js@1.16.0

Details

Affected versions of `plotly.js` are vulnerable to cross-site scripting if an attacker can convince a user to visit a malicious plot on a site using this package.

## Recommendation

Update to 1.16.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/plotly.js
Introduced in: 0Fixed in: 1.16.0
Fixnpm install plotly.js@1.16.0

References