VDB
Sign up
MEDIUM5.4

GHSA-j6p2-cx3w-6jcp

Cross-Site Scripting in backbone

Quick fix

GHSA-j6p2-cx3w-6jcp — backbone: upgrade to the fixed version with the command below.

npm install backbone@0.5.0

Details

Affected versions of `backbone` are vulnerable to cross-site scripting when users are allowed to supply input to the `Model#Escape` function, and the output is then written to the DOM.

The vulnerability occurs as a result of the regular expression used to encode metacharacters failing to take HTML Entities such as `<` into account.

## Recommendation

Update to version 0.5.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/backbone
Introduced in: 0.3.3Fixed in: 0.5.0
Fixnpm install backbone@0.5.0

References