GHSA-gm29-35c7-8cfw
Dashboard / Vulnerabilities / GHSA-gm29-35c7-8cfw
Summary: Cross-Site Scripting in buttle
Details: All versions of `buttle` are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code. ## Recommendation No fix is currently available. Consider using an alternative package until a fix is made available.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-5422, https://hackerone.com/reports/331032, https://hackerone.com/reports/331110, https://github.com/advisories/GHSA-gm29-35c7-8cfw, https://www.npmjs.com/advisories/1009, https://www.npmjs.com/advisories/667
Affected packages
Package
Name: buttle
Purl: pkg:npm/buttle
Affected ranges
Type: SEMVER
Events:
