MEDIUM
GHSA-87mg-h5r3-hw88
Cross-Site Scripting in bootbox
Details
All version of `bootbox` are vulnerable to Cross-Site Scripting. The package does not sanitize user input in the provided dialog boxes, allowing attackers to inject HTML code and execute arbitrary JavaScript.
## Recommendation
Sanitize user input being passed to `bootbox` or consider using an alternative package.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/bootbox
Introduced in:
0No fixed version published yet for bootbox (npm). Pin to a known-safe version or switch to an alternative.