VDB
Sign up
MEDIUM4.6

GHSA-q54r-r9pr-w7qv

Hexo Vulnerable to XSS

Quick fix

GHSA-q54r-r9pr-w7qv — hexo: upgrade to the fixed version with the command below.

npm install hexo@6.0.0

Details

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/hexo
Introduced in: 0.0.1Fixed in: 6.0.0
Fixnpm install hexo@6.0.0

References