VDB
Sign up
MEDIUM6.1

GHSA-7752-f4gf-94gc

Materialize-css vulnerable to Cross-site Scripting in autocomplete component

Quick fix

GHSA-7752-f4gf-94gc — @materializecss/materialize: upgrade to the fixed version with the command below.

npm install @materializecss/materialize@1.1.0-alpha

Details

All versions of `materialize-css` are vulnerable to Cross-Site Scripting. The `autocomplete` component does not sufficiently sanitize user input, allowing an attacker to execute arbitrary JavaScript code if the malicious input is rendered by a user.

## Recommendation

No fix is currently available. Consider using an alternative module until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/materialize-css
Introduced in: 0

No fixed version published yet for materialize-css (npm). Pin to a known-safe version or switch to an alternative.

npm/@materializecss/materialize
Introduced in: 0Fixed in: 1.1.0-alpha
Fixnpm install @materializecss/materialize@1.1.0-alpha

References