MEDIUM
GHSA-xc6g-ggrc-qq4r
Cross-Site Scripting in sanitize-html
Quick fix
GHSA-xc6g-ggrc-qq4r — sanitize-html: upgrade to the fixed version with the command below.
npm install sanitize-html@1.11.4Details
Affected versions of `sanitize-html` are vulnerable to cross-site scripting when allowedTags includes at least one `nonTextTag`.
## Proof of Concept
```js var sanitizeHtml = require('sanitize-html');
var dirty = '!<textarea></textarea><svg/onload=prompt`xs`></textarea>!'; var clean = sanitizeHtml(dirty, { allowedTags: [ 'textarea' ] });
console.log(clean);
// !<textarea></textarea><svg/onload=prompt`xs`></textarea>! ```
## Recommendation
Update to version 1.11.4 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-16016[ADVISORY]
- https://github.com/punkave/sanitize-html/issues/100[WEB]
- https://github.com/punkave/sanitize-html/commit/5d205a1005ba0df80e21d8c64a15bb3accdb2403[WEB]
- https://github.com/punkave/sanitize-html/commit/5d205a1005ba0df80e21d8c64a15bb3accdb2403)))[WEB]
- https://github.com/advisories/GHSA-xc6g-ggrc-qq4r[ADVISORY]
- https://npmjs.com/package/sanitize-html#discarding-the-entire-contents-of-a-disallowed-tag[WEB]
- https://www.npmjs.com/advisories/154[WEB]