MEDIUM6.1
GHSA-j4rv-pr9g-q8jv
mxGraph vulnerable to cross-site scripting in setTooltips function
Details
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the `setTooltips()` function.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/mxgraph
Introduced in:
0No fixed version published yet for mxgraph (npm). Pin to a known-safe version or switch to an alternative.