Lucene search

K
nodejsTungpunNODEJS:1000
HistoryJun 19, 2019 - 2:58 a.m.

Cross-Site Scripting

2019-06-1902:58:37
tungpun
www.npmjs.com
4

0.001 Low

EPSS

Percentile

32.7%

Overview

Versions of public prior to 0.1.4 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim’s browser through files with names containing malicious code.

Recommendation

Upgrade to version 0.1.4 or later.

References

CPENameOperatorVersion
publiclt0.1.4

0.001 Low

EPSS

Percentile

32.7%