VDB
Sign up
HIGH

GHSA-w4vp-3mq7-7v82

Cross-Site Scripting in lazysizes

Quick fix

GHSA-w4vp-3mq7-7v82 — lazysizes: upgrade to the fixed version with the command below.

npm install lazysizes@5.2.1-rc1

Details

Versions of `lazysizes` prior to 5.2.1-rc1 are vulnerable to Cross-Site Scripting. The `video-embed` plugin fails to sanitize the following attributes: data-vimeo, `data-vimeoparams`, `data-youtube` and `data-ytparams`. This allows attackers to execute arbitrary JavaScript in a victim's browser if the attacker has control over the vulnerable attributes.

## Recommendation

Upgrade to version 5.2.1-rc1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/lazysizes
Introduced in: 0Fixed in: 5.2.1-rc1
Fixnpm install lazysizes@5.2.1-rc1

References