VDB
Sign up
MEDIUM4.8

GHSA-7cv6-gvx3-m54m

Cross-Site Scripting in keystone

Quick fix

GHSA-7cv6-gvx3-m54m — keystone: upgrade to the fixed version with the command below.

npm install keystone@4.0.0-beta7

Details

Versions of `keystone` prior to 4.0.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to properly encode rendered HTML on admin-created blog posts. This allows attackers to execute arbitrary JavaScript in the victim's browser. Exploiting this vulnerability requires having access to an admin account.

## Recommendation

Update to version 4.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/keystone
Introduced in: 0Fixed in: 4.0.0-beta7
Fixnpm install keystone@4.0.0-beta7

References