VDB
Sign up
MEDIUM6.1

GHSA-hfj4-96f7-6r5g

Cross-Site Scripting in html-janitor

Quick fix

GHSA-hfj4-96f7-6r5g — html-janitor: upgrade to the fixed version with the command below.

npm install html-janitor@2.0.3

Details

Versions of `html-janitor` prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS).

This is exploitable if user-controlled data is passed into the modules `clean()` function.

## Recommendation

No fix is currently available for this vulnerability. It is recommended to use an alternative module for HTML sanitization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/html-janitor
Introduced in: 0Fixed in: 2.0.3
Fixnpm install html-janitor@2.0.3

References