MEDIUM6.1
GHSA-7752-f4gf-94gc
Materialize-css vulnerable to Cross-site Scripting in autocomplete component
Quick fix
GHSA-7752-f4gf-94gc — @materializecss/materialize: upgrade to the fixed version with the command below.
npm install @materializecss/materialize@1.1.0-alphaDetails
All versions of `materialize-css` are vulnerable to Cross-Site Scripting. The `autocomplete` component does not sufficiently sanitize user input, allowing an attacker to execute arbitrary JavaScript code if the malicious input is rendered by a user.
## Recommendation
No fix is currently available. Consider using an alternative module until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/materialize-css
Introduced in:
0No fixed version published yet for materialize-css (npm). Pin to a known-safe version or switch to an alternative.
npm/@materializecss/materialize
Introduced in:
0Fixed in: 1.1.0-alphaFix
npm install @materializecss/materialize@1.1.0-alpha