VDB
Sign up
HIGH8.7

GHSA-gr4j-r575-g665

Cross-Site Scripting in highcharts

Quick fix

GHSA-gr4j-r575-g665 — highcharts: upgrade to the fixed version with the command below.

npm install highcharts@7.2.2

Details

Versions of `highcharts` prior to 7.2.2 or 8.1.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize `href` values and does not restrict URL schemes, allowing attackers to execute arbitrary JavaScript in a victim's browser if they click the link.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/highcharts
Introduced in: 0Fixed in: 7.2.2
Fixnpm install highcharts@7.2.2
npm/highcharts
Introduced in: 8.0.0Fixed in: 8.1.1
Fixnpm install highcharts@8.1.1

References