GHSA-gh4g-3gm9-5wrq
Dashboard / Vulnerabilities / GHSA-gh4g-3gm9-5wrq
Summary: Cross-Site Scripting in shave
Details: Versions of `shave` prior to 2.5.3 are vulnerable to Cross-Site Scripting. The `shave` package overwrites HTML elements and in doing so fails to properly encode the output. If encoded HTML input is passed into `shave` the output will be decoded which may lead to Cross-Site Scripting. ## Recommendation Upgrade to version 2.5.3 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-12313, https://github.com/dollarshaveclub/shave/commit/da7371b0531ba14eae48ef1bb1456a3de4cfa954#diff-074799b511e4b61923dfd3f2a3bf9b54R67, https://github.com/dollarshaveclub/shave/compare/852b537...da7371b, https://www.npmjs.com/advisories/822
Affected packages
Package
Name: shave
Purl: pkg:npm/shave
Affected ranges
Type: SEMVER
Events:
