VDB
Sign up
MEDIUM6.1

GHSA-hhrp-qm88-xjr3

Valine HTML Injection

Quick fix

GHSA-hhrp-qm88-xjr3 — valine: upgrade to the fixed version with the command below.

npm install valine@1.3.4

Details

An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/valine
Introduced in: 0Fixed in: 1.3.4
Fixnpm install valine@1.3.4

References