VDB
Sign up
MEDIUM6.3

GHSA-gmch-cm2p-9qw9

Cross-site Scripting in lightning-server

Details

This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/lightning-server
Introduced in: 0

No fixed version published yet for lightning-server (npm). Pin to a known-safe version or switch to an alternative.

References