MEDIUM6.5
GHSA-588m-9qg5-35pq
Reverse Tabnabbing in quill
Quick fix
GHSA-588m-9qg5-35pq — quill: upgrade to the fixed version with the command below.
npm install quill@1.3.7Details
Versions of `quill` prior to 1.3.7 are vulnerable to [Reverse Tabnabbing](https://www.owasp.org/index.php/Reverse_Tabnabbing). The package uses `target='_blank'` in anchor tags, allowing attackers to access `window.opener` for the original page when opening links. This is commonly used for phishing attacks.
## Recommendation
No fix is currently available. Consider using an alternative package until a fix is made available.
Are you affected?
Enter the version of the package you're using.