MEDIUM4.6
GHSA-vqr3-vrrg-f3jh
NodeBB Cross-site scripting (XSS) vulnerability
Quick fix
GHSA-vqr3-vrrg-f3jh — nodebb: upgrade to the fixed version with the command below.
npm install nodebb@3.11.1Details
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.
Are you affected?
Enter the version of the package you're using.