VDB
Sign up
LOW

GHSA-7jfh-2xc9-ccv7

Cross-Site Scripting in public

Quick fix

GHSA-7jfh-2xc9-ccv7 — public: upgrade to the fixed version with the command below.

npm install public@0.1.4

Details

All versions of `public` are vulnerable to stored cross-site scripting (XSS).

## Recommendation

No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/public
Introduced in: 0Fixed in: 0.1.4
Fixnpm install public@0.1.4
npm/public

No fixed version published yet for public (npm). Pin to a known-safe version or switch to an alternative.

References