MEDIUM5.4
GHSA-4jqw-vfmj-9rmh
Cross-site Scripting in yapi-vendor
Details
Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/yapi-vendor
Introduced in:
0No fixed version published yet for yapi-vendor (npm). Pin to a known-safe version or switch to an alternative.