GHSA-hfj4-96f7-6r5g
Dashboard / Vulnerabilities / GHSA-hfj4-96f7-6r5g
Summary: Cross-Site Scripting in html-janitor
Details: Versions of `html-janitor` prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS). This is exploitable if user-controlled data is passed into the modules `clean()` function. ## Recommendation No fix is currently available for this vulnerability. It is recommended to use an alternative module for HTML sanitization.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-0931, https://github.com/guardian/html-janitor/issues/34, https://hackerone.com/reports/308155, https://github.com/advisories/GHSA-hfj4-96f7-6r5g, https://www.npmjs.com/advisories/576
Affected packages
Package
Name: html-janitor
Purl: pkg:npm/html-janitor
Affected ranges
Type: SEMVER
Events:
