VDB
Sign up
MEDIUM6.1

GHSA-cx3j-qqxj-9597

Critters Cross-site Scripting Vulnerability

Quick fix

GHSA-cx3j-qqxj-9597 — critters: upgrade to the fixed version with the command below.

npm install critters@0.0.20

Details

### Impact Critters version 0.0.17-0.0.19 have an issue when parsing the HTML which leads to a potential [cross-site scripting (XSS)](https://owasp.org/www-community/attacks/xss/) bug.

### Patches The bug has been fixed in `v0.0.20`.

### Workarounds Upgrading Critters version to `>0.0.20` is the easiest fix. This is a non breaking version upgrade so we recommend all users to use `v0.0.20`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/critters
Introduced in: 0.0.17Fixed in: 0.0.20
Fixnpm install critters@0.0.20

References