VDB
Sign up
MEDIUM6.1

GHSA-qhxp-v273-g94h

sanitize-html is vulnerable to XSS through incomprehensive sanitization

Quick fix

GHSA-qhxp-v273-g94h — sanitize-html: upgrade to the fixed version with the command below.

npm install sanitize-html@2.0.0-beta

Details

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sanitize-html
Introduced in: 0Fixed in: 2.0.0-beta
Fixnpm install sanitize-html@2.0.0-beta

References