HIGH
GHSA-phph-xpj4-wvcv
Cross-Site Scripting in hexo-admin
Details
All versions of `hexo-admin` are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize rendered markdown, allowing attackers to execute arbitrary JavaScript in a victim's browser if they are able to create new posts.
## Recommendation
No fix is currently available. Consider using an alternative package until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/hexo-admin
Introduced in:
0.0.0No fixed version published yet for hexo-admin (npm). Pin to a known-safe version or switch to an alternative.