HIGH7.1
GHSA-rpc5-pm7q-hjmp
billboard.js is vulnerable to XSS during chart option binding
Quick fix
GHSA-rpc5-pm7q-hjmp — billboard.js: upgrade to the fixed version with the command below.
npm install billboard.js@3.18.0Details
billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.
Are you affected?
Enter the version of the package you're using.