VDB
Sign up
MEDIUM6.1

GHSA-wg96-3933-j2w5

Cross-Site Scripting in sanitize-html

Quick fix

GHSA-wg96-3933-j2w5 — sanitize-html: upgrade to the fixed version with the command below.

npm install sanitize-html@1.2.3

Details

Affected versions of `sanitize-html` are vulnerable to cross-site scripting.

## Proof of Concept:

`<IMG SRC= onmouseover="alert('XSS');">` produces the following:

`<img src="onmouseover="alert('XSS');"" />` This is definitely invalid HTML, but would suggest that it's being interpreted incorrectly by the parser.

## Recommendation

Update to version 1.2.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sanitize-html
Introduced in: 0Fixed in: 1.2.3
Fixnpm install sanitize-html@1.2.3

References