Lucene search

K
nodejsAnonymousNODEJS:1675
HistoryMay 06, 2021 - 4:14 p.m.

Improper Input Validation

2021-05-0616:14:51
Anonymous
www.npmjs.com
18
security
input validation
sanitize-html
internationalized domain name
cve-2021-26539
github advisory

EPSS

0.001

Percentile

49.3%

Overview

sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the “allowedIframeHostnames” option.

Recommendation

Upgrade to version 2.3.1 or later

References