VDB
Sign up
MEDIUM6.1

GHSA-qpjp-7rp2-9c3f

Moderate severity vulnerability that affects validator

Quick fix

GHSA-qpjp-7rp2-9c3f — validator: upgrade to the fixed version with the command below.

npm install validator@1.1.0

Details

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/validator
Introduced in: 0Fixed in: 1.1.0
Fixnpm install validator@1.1.0

References