GHSA-g3fq-3v3g-mh32
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in @nextcloud/dialogs
Quick fix
GHSA-g3fq-3v3g-mh32 — @nextcloud/dialogs: upgrade to the fixed version with the command below.
npm install @nextcloud/dialogs@3.1.2Details
### Impact
The Nextcloud dialogs library before 3.1.2 did insufficiently escape text input passed to a toast. If your application displays toasts with user-supplied input, this could lead to a XSS vulnerability.
_Note_: Nextcloud Server employs a strict Content Security Policy that mitigates the risk of these XSS vulnerabilities.
### Patches
The vulnerability has been patched in version 3.1.2. If you need to display HTML in the toast, explicitly pass the `options.isHTML` config flag.
### Workarounds
Make sure no user-supplied input flows into toasts.
Are you affected?
Enter the version of the package you're using.