VDB
Sign up
MEDIUM6.1

GHSA-5h7x-68wj-jhwc

Docsify vulnerable to cross-site scripting due to mishandled encoding

Quick fix

GHSA-5h7x-68wj-jhwc — docsify: upgrade to the fixed version with the command below.

npm install docsify@4.12.2

Details

docsify versions 4.12.1 and earlier are vulnerable to cross-site scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the `"` character.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/docsify
Introduced in: 0Fixed in: 4.12.2
Fixnpm install docsify@4.12.2

References