VDB
Sign up
MEDIUM4.6

GHSA-g3fq-3v3g-mh32

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in @nextcloud/dialogs

Quick fix

GHSA-g3fq-3v3g-mh32 — @nextcloud/dialogs: upgrade to the fixed version with the command below.

npm install @nextcloud/dialogs@3.1.2

Details

### Impact

The Nextcloud dialogs library before 3.1.2 did insufficiently escape text input passed to a toast. If your application displays toasts with user-supplied input, this could lead to a XSS vulnerability.

_Note_: Nextcloud Server employs a strict Content Security Policy that mitigates the risk of these XSS vulnerabilities.

### Patches

The vulnerability has been patched in version 3.1.2. If you need to display HTML in the toast, explicitly pass the `options.isHTML` config flag.

### Workarounds

Make sure no user-supplied input flows into toasts.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@nextcloud/dialogs
Introduced in: 0Fixed in: 3.1.2
Fixnpm install @nextcloud/dialogs@3.1.2

References