MEDIUM6.1
GHSA-wg96-3933-j2w5
Cross-Site Scripting in sanitize-html
Quick fix
GHSA-wg96-3933-j2w5 — sanitize-html: upgrade to the fixed version with the command below.
npm install sanitize-html@1.2.3Details
Affected versions of `sanitize-html` are vulnerable to cross-site scripting.
## Proof of Concept:
`<IMG SRC= onmouseover="alert('XSS');">` produces the following:
`<img src="onmouseover="alert('XSS');"" />` This is definitely invalid HTML, but would suggest that it's being interpreted incorrectly by the parser.
## Recommendation
Update to version 1.2.3 or later.
Are you affected?
Enter the version of the package you're using.