VDB
Sign up
MEDIUM6.1

GHSA-q854-j362-cfq9

Cross-site Scripting in jsoneditor

Quick fix

GHSA-q854-j362-cfq9 — jsoneditor: upgrade to the fixed version with the command below.

npm install jsoneditor@9.0.2

Details

Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jsoneditor
Introduced in: 0Fixed in: 9.0.2
Fixnpm install jsoneditor@9.0.2

References