VDB
Sign up
MEDIUM5.4

GHSA-hg2p-2cvq-4ppv

Cross-site scripting in lazysizes

Quick fix

GHSA-hg2p-2cvq-4ppv — lazysizes: upgrade to the fixed version with the command below.

npm install lazysizes@5.2.1

Details

lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: `data-vimeo`, `data-vimeoparams`, `data-youtube` and `data-ytparams` which can be abused to inject malicious JavaScript.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/lazysizes
Introduced in: 0Fixed in: 5.2.1
Fixnpm install lazysizes@5.2.1

References