VDB
Sign up
HIGH

GHSA-jj6g-7j8p-7gf2

Cross-Site Scripting in bracket-template

Details

All versions of `bracket-template` are vulnerable to stored cross-site scripting (XSS). This is exploitable when a variable passed in via a GET parameter is used in a template.

## Recommendation

No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bracket-template
Introduced in: 0

No fixed version published yet for bracket-template (npm). Pin to a known-safe version or switch to an alternative.

References