Cross-Site Scripting in webpack-bundle-analyzer
Moderate severity
GitHub Reviewed
Published
May 23, 2019
to the GitHub Advisory Database
•
Updated Apr 13, 2023
Description
Reviewed
May 23, 2019
Published to the GitHub Advisory Database
May 23, 2019
Last updated
Apr 13, 2023
Versions of
webpack-bundle-analyzer
prior to 3.3.2 are vulnerable to Cross-Site Scripting. The package usesJSON.stringify()
without properly escaping input which may lead to Cross-Site Scripting.Recommendation
Upgrade to version 3.3.2 or later.
References