MEDIUM6.1
GHSA-cx3j-qqxj-9597
Critters Cross-site Scripting Vulnerability
Quick fix
GHSA-cx3j-qqxj-9597 — critters: upgrade to the fixed version with the command below.
npm install critters@0.0.20Details
### Impact Critters version 0.0.17-0.0.19 have an issue when parsing the HTML which leads to a potential [cross-site scripting (XSS)](https://owasp.org/www-community/attacks/xss/) bug.
### Patches The bug has been fixed in `v0.0.20`.
### Workarounds Upgrading Critters version to `>0.0.20` is the easiest fix. This is a non breaking version upgrade so we recommend all users to use `v0.0.20`.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/GoogleChromeLabs/critters/security/advisories/GHSA-cx3j-qqxj-9597[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-3481[ADVISORY]
- https://github.com/GoogleChromeLabs/critters/pull/133[WEB]
- https://github.com/GoogleChromeLabs/critters/commit/7757902c9e0b3285d516359b3cb602cd9d50d80e[WEB]
- https://github.com/GoogleChromeLabs/critters[PACKAGE]