MEDIUM6.1
GHSA-q8gg-vj6m-hgmj
@braintree/sanitize-url Cross-site Scripting vulnerability
Quick fix
GHSA-q8gg-vj6m-hgmj — @braintree/sanitize-url: upgrade to the fixed version with the command below.
npm install @braintree/sanitize-url@6.0.1Details
sanitize-url (aka @braintree/sanitize-url) before 6.0.1 allows XSS via HTML entities.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@braintree/sanitize-url
Introduced in:
0Fixed in: 6.0.1Fix
npm install @braintree/sanitize-url@6.0.1References
- https://nvd.nist.gov/vuln/detail/CVE-2022-48345[ADVISORY]
- https://github.com/braintree/sanitize-url/commit/d4bdc89f1743fe3cdb7c3f24b06e4c875f349b0c[WEB]
- https://github.com/braintree/sanitize-url[PACKAGE]
- https://github.com/braintree/sanitize-url/compare/v6.0.0...v6.0.1[WEB]
- https://github.com/braintree/sanitize-url/compare/v6.0.1...v6.0.2[WEB]