VDB
Sign up
HIGH7.5

GHSA-vp4f-wxgw-7x8x

Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client

Quick fix

GHSA-vp4f-wxgw-7x8x — @dcl/single-sign-on-client: upgrade to the fixed version with the command below.

npm install @dcl/single-sign-on-client@0.1.0

Details

### Impact Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix

```ts SSO.init('javascript:alert("javascript successfully injected")') ```

### Patches

This vulnerability was patched on version `0.1.0`

### Workarounds

This vulnerability can be prevented if user input correctly sanitized or there is no user input pass to the `init` function

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@dcl/single-sign-on-client
Introduced in: 0Fixed in: 0.1.0
Fixnpm install @dcl/single-sign-on-client@0.1.0

References