LOW3.7
GHSA-qxg5-2qff-p49r
Passing in a non-string 'html' argument can lead to unsanitized output
Quick fix
GHSA-qxg5-2qff-p49r — striptags: upgrade to the fixed version with the command below.
npm install striptags@3.2.0Details
A type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array-like object is passed in as the `html` parameter. This can be abused by an attacker who can control the shape of their input, e.g. if query parameters are passed directly into the function.
### Impact
XSS
### Patches
`3.2.0`
### Workarounds
Ensure that the `html` parameter is a string before calling the function.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ericnorris/striptags/security/advisories/GHSA-qxg5-2qff-p49r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-32696[ADVISORY]
- https://github.com/ericnorris/striptags/commit/f252a6b0819499cd65403707ebaf5cc925f2faca[WEB]
- https://github.com/ericnorris/striptags/releases/tag/v3.2.0[WEB]
- https://www.npmjs.com/package/striptags[WEB]