MEDIUM6.4
GHSA-vggc-6pg2-xvp9
Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling
Details
Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary JavaScript in victims' browsers.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/vulnogram
Introduced in:
0No fixed version published yet for vulnogram (npm). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/Vulnogram/Vulnogram/security/advisories/GHSA-pg4p-2985-gvxr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-32774[ADVISORY]
- https://github.com/Vulnogram/Vulnogram/commit/2f0e21b113c58124084c7b74c9768fc241126a05[WEB]
- https://github.com/Vulnogram/Vulnogram[PACKAGE]
- https://www.vulncheck.com/advisories/vulnogram-stored-cross-site-scripting-via-comment-hypertext[WEB]