VDB
Sign up
CRITICAL9.8

GHSA-h4j5-c7cj-74xg

xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection

Quick fix

GHSA-h4j5-c7cj-74xg — xmlhttprequest: upgrade to the fixed version with the command below.

npm install xmlhttprequest@1.7.0

Details

This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (`async=False` on `xhr.open`), malicious user input flowing into `xhr.send` could result in arbitrary code being injected and run.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/xmlhttprequest
Introduced in: 0Fixed in: 1.7.0
Fixnpm install xmlhttprequest@1.7.0
npm/xmlhttprequest-ssl
Introduced in: 0Fixed in: 1.6.2
Fixnpm install xmlhttprequest-ssl@1.6.2

References