VDB
Sign up
MEDIUM6.1

GHSA-jr64-pggr-j8xj

Shiba vulnerable to XSS leading to code execution

Quick fix

GHSA-jr64-pggr-j8xj — shiba: upgrade to the fixed version with the command below.

npm install shiba@1.1.1

Details

Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/shiba
Introduced in: 0Fixed in: 1.1.1
Fixnpm install shiba@1.1.1

References