VDB
Sign up
LOW3.7

GHSA-qxg5-2qff-p49r

Passing in a non-string 'html' argument can lead to unsanitized output

Quick fix

GHSA-qxg5-2qff-p49r — striptags: upgrade to the fixed version with the command below.

npm install striptags@3.2.0

Details

A type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array-like object is passed in as the `html` parameter. This can be abused by an attacker who can control the shape of their input, e.g. if query parameters are passed directly into the function.

### Impact

XSS

### Patches

`3.2.0`

### Workarounds

Ensure that the `html` parameter is a string before calling the function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/striptags
Introduced in: 0Fixed in: 3.2.0
Fixnpm install striptags@3.2.0

References