GHSA-pgr8-jg6h-8gw6
Dashboard / Vulnerabilities / GHSA-pgr8-jg6h-8gw6
GHSA-pgr8-jg6h-8gw6
Summary: Cross-Site Scripting in webpack-bundle-analyzer
Details: Versions of `webpack-bundle-analyzer` prior to 3.3.2 are vulnerable to Cross-Site Scripting. The package uses `JSON.stringify()` without properly escaping input which may lead to Cross-Site Scripting. ## Recommendation Upgrade to version 3.3.2 or later.
References: https://github.com/webpack-contrib/webpack-bundle-analyzer/issues/263, https://github.com/webpack-contrib/webpack-bundle-analyzer/pull/264, https://github.com/webpack-contrib/webpack-bundle-analyzer/commit/20f2b4c553ee343f491faf63e39427fba9908c7c, https://snyk.io/vuln/SNYK-JS-WEBPACKBUNDLEANALYZER-174190, https://www.npmjs.com/advisories/826
Affected packages
Package
Name: webpack-bundle-analyzer
Purl: pkg:npm/webpack-bundle-analyzer
Affected ranges
Type: SEMVER
Events:
