VDB
Sign up
MEDIUM

GHSA-87mg-h5r3-hw88

Cross-Site Scripting in bootbox

Details

All version of `bootbox` are vulnerable to Cross-Site Scripting. The package does not sanitize user input in the provided dialog boxes, allowing attackers to inject HTML code and execute arbitrary JavaScript.

## Recommendation

Sanitize user input being passed to `bootbox` or consider using an alternative package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootbox
Introduced in: 0

No fixed version published yet for bootbox (npm). Pin to a known-safe version or switch to an alternative.

References