MEDIUM5.4
GHSA-hg2p-2cvq-4ppv
Cross-site scripting in lazysizes
Quick fix
GHSA-hg2p-2cvq-4ppv — lazysizes: upgrade to the fixed version with the command below.
npm install lazysizes@5.2.1Details
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: `data-vimeo`, `data-vimeoparams`, `data-youtube` and `data-ytparams` which can be abused to inject malicious JavaScript.
Are you affected?
Enter the version of the package you're using.