MEDIUM5.4
GHSA-8w65-xjc5-9w79
Cross-Site Scripting in node-red
Quick fix
GHSA-8w65-xjc5-9w79 — node-red: upgrade to the fixed version with the command below.
npm install node-red@0.20.8Details
Versions of `node-red` prior to 0.20.8are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize the `name` field in new Flows, allowing attackers to execute arbitrary JavaScript in the victim's browser.
## Recommendation
Upgrade to version 0.18.6 or later.
Are you affected?
Enter the version of the package you're using.