VDB
Sign up
MEDIUM6.1

GHSA-pxpf-v376-7xx5

tagify can pass a malicious placeholder to initiate the cross-site scripting (XSS) payload

Quick fix

GHSA-pxpf-v376-7xx5 — @yaireo/tagify: upgrade to the fixed version with the command below.

npm install @yaireo/tagify@4.9.8

Details

This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the cross-site scripting (XSS) payload.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@yaireo/tagify
Introduced in: 0Fixed in: 4.9.8
Fixnpm install @yaireo/tagify@4.9.8

References