MEDIUM4.8
GHSA-m52x-29pq-w3vv
Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript
Quick fix
GHSA-m52x-29pq-w3vv — pannellum: upgrade to the fixed version with the command below.
npm install pannellum@2.5.5Details
Versions of `pannellum` prior to 2.5.6 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize URLs for data URIs, which may allow attackers to execute arbitrary code in a victim's browser.
## Recommendation
Upgrade to version 2.5.6 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/mpetroff/pannellum/security/advisories/GHSA-m52x-29pq-w3vv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2019-16763[ADVISORY]
- https://github.com/mpetroff/pannellum/commit/cc2f3d99953de59db908e0c6efd1c2c17f7c6914[WEB]
- https://github.com/advisories/GHSA-m52x-29pq-w3vv[ADVISORY]
- https://github.com/mpetroff/pannellum[PACKAGE]
- https://www.npmjs.com/advisories/1418[WEB]