VDB
Sign up
MEDIUM4.6

GHSA-f44m-65h3-99vc

tarteaucitron.js vulnerable to Cross-site Scripting

Quick fix

GHSA-f44m-65h3-99vc — tarteaucitronjs: upgrade to the fixed version with the command below.

npm install tarteaucitronjs@1.13.1

Details

Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/tarteaucitronjs
Introduced in: 0Fixed in: 1.13.1
Fixnpm install tarteaucitronjs@1.13.1

References