GHSA-vvhj-v88f-5gxr
ghtml Cross-Site Scripting (XSS) vulnerability
Quick fix
GHSA-vvhj-v88f-5gxr — ghtml: upgrade to the fixed version with the command below.
npm install ghtml@2.0.0Details
## Summary
It is possible to introduce user-controlled JavaScript code and trigger a Cross-Site Scripting (XSS) vulnerability in some cases.
## Actions Taken
- Updated the documentation to clarify that while `ghtml` escapes characters with special meaning in HTML, it does not provide comprehensive protection against all types of XSS attacks in every scenario. **_This aligns with the approach taken by other template engines. Developers should be cautious and take additional measures to sanitize user input and prevent potential vulnerabilities._** More reading: https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html - The backtick character (`) is now also escaped to prevent the creation of strings in most cases where a malicious actor somehow gains the ability to write JavaScript. This does not provide comprehensive protection either.
Are you affected?
Enter the version of the package you're using.