HIGH
GHSA-5g6j-8hv4-vfgj
Cross-Site Scripting in node-red
Quick fix
GHSA-5g6j-8hv4-vfgj — node-red: upgrade to the fixed version with the command below.
npm install node-red@0.18.6Details
Versions of `node-red` prior to 0.18.6 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize the `name` field in new items, allowing attackers to execute arbitrary JavaScript in the victim's browser.
## Recommendation
Upgrade to version 0.18.6 or later.
Are you affected?
Enter the version of the package you're using.