VDB
Sign up
MEDIUM

GHSA-xc6g-ggrc-qq4r

Cross-Site Scripting in sanitize-html

Quick fix

GHSA-xc6g-ggrc-qq4r — sanitize-html: upgrade to the fixed version with the command below.

npm install sanitize-html@1.11.4

Details

Affected versions of `sanitize-html` are vulnerable to cross-site scripting when allowedTags includes at least one `nonTextTag`.

## Proof of Concept

```js var sanitizeHtml = require('sanitize-html');

var dirty = '!<textarea>&lt;/textarea&gt;<svg/onload=prompt`xs`&gt;</textarea>!'; var clean = sanitizeHtml(dirty, { allowedTags: [ 'textarea' ] });

console.log(clean);

// !<textarea></textarea><svg/onload=prompt`xs`></textarea>! ```

## Recommendation

Update to version 1.11.4 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sanitize-html
Introduced in: 0Fixed in: 1.11.4
Fixnpm install sanitize-html@1.11.4

References