HIGH
GHSA-w4vp-3mq7-7v82
Cross-Site Scripting in lazysizes
Quick fix
GHSA-w4vp-3mq7-7v82 — lazysizes: upgrade to the fixed version with the command below.
npm install lazysizes@5.2.1-rc1Details
Versions of `lazysizes` prior to 5.2.1-rc1 are vulnerable to Cross-Site Scripting. The `video-embed` plugin fails to sanitize the following attributes: data-vimeo, `data-vimeoparams`, `data-youtube` and `data-ytparams`. This allows attackers to execute arbitrary JavaScript in a victim's browser if the attacker has control over the vulnerable attributes.
## Recommendation
Upgrade to version 5.2.1-rc1 or later.
Are you affected?
Enter the version of the package you're using.