MEDIUM6.1
GHSA-hfj4-96f7-6r5g
Cross-Site Scripting in html-janitor
Quick fix
GHSA-hfj4-96f7-6r5g — html-janitor: upgrade to the fixed version with the command below.
npm install html-janitor@2.0.3Details
Versions of `html-janitor` prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS).
This is exploitable if user-controlled data is passed into the modules `clean()` function.
## Recommendation
No fix is currently available for this vulnerability. It is recommended to use an alternative module for HTML sanitization.
Are you affected?
Enter the version of the package you're using.