VDB
Sign up
HIGH

GHSA-7p6w-x2gr-rrf8

ag-grid Cross-Site Scripting vulnerability

Quick fix

GHSA-7p6w-x2gr-rrf8 — ag-grid: upgrade to the fixed version with the command below.

npm install ag-grid@14.0.0

Details

Versions of `ag-grid` prior to 14.0.0 are vulnerable to Cross-Site Scripting (XSS). Grid contents are not properly sanitized and may allow attackers to execute arbitrary JavaScript if user input is rendered in the grid.

## Recommendation

Upgrade to version 14.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ag-grid
Introduced in: 0Fixed in: 14.0.0
Fixnpm install ag-grid@14.0.0

References