VDB
Sign up
MEDIUM6.1

GHSA-3j7m-hmh3-9jmp

Cross-Site Scripting in sanitize-html

Quick fix

GHSA-3j7m-hmh3-9jmp — sanitize-html: upgrade to the fixed version with the command below.

npm install sanitize-html@1.4.3

Details

Affected versions of `sanitize-html` do not sanitize input recursively, which may allow an attacker to execute arbitrary Javascript.

## Recommendation

Update to version 1.4.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sanitize-html
Introduced in: 0Fixed in: 1.4.3
Fixnpm install sanitize-html@1.4.3

References