VDB
Sign up
MEDIUM6.1

GHSA-grjp-4jmr-mjcw

express-xss-sanitizer vulnerable to Prototype Pollution via allowedTags attribute

Quick fix

GHSA-grjp-4jmr-mjcw — express-xss-sanitizer: upgrade to the fixed version with the command below.

npm install express-xss-sanitizer@1.1.3

Details

The package express-xss-sanitizer before 1.1.3 is vulnerable to Prototype Pollution via the `allowedTags` attribute, allowing the attacker to bypass xss sanitization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express-xss-sanitizer
Introduced in: 0Fixed in: 1.1.3
Fixnpm install express-xss-sanitizer@1.1.3

References