MEDIUM6.1
GHSA-8p5p-ff7x-hw7q
Cross-Site Scripting in public
Quick fix
GHSA-8p5p-ff7x-hw7q — public: upgrade to the fixed version with the command below.
npm install public@0.1.4Details
Versions of `public` prior to 0.1.4 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code.
## Recommendation
Upgrade to version 0.1.4 or later.
Are you affected?
Enter the version of the package you're using.