MEDIUM6.1
GHSA-5p26-hw7f-3cpr
Cross-Site Scripting in html-pages
Details
All versions of `html-pages` are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize folder names, allowing attackers to execute arbitrary JavaScript in the victim's browser through folders with names containing malicious code.
## Recommendation
No fix is currently available. Consider using an alternative package until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/html-pages
Introduced in:
0No fixed version published yet for html-pages (npm). Pin to a known-safe version or switch to an alternative.