VDB
Sign up
MEDIUM6.1

GHSA-649c-x44h-4q7v

Tnantoka/public XSS Vulnerability

Quick fix

GHSA-649c-x44h-4q7v — public: upgrade to the fixed version with the command below.

npm install public@0.1.4

Details

A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanitization of the file/folder names before rendering.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/public
Introduced in: 0Fixed in: 0.1.4
Fixnpm install public@0.1.4

References