Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhxp-v273-g94h

Опубликовано: 08 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

sanitize-html is vulnerable to XSS through incomprehensive sanitization

sanitize-html prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The sanitizeHtml() function in index.js does not sanitize content when using the custom transformTags option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

Пакеты

Наименование

sanitize-html

npm
Затронутые версииВерсия исправления

< 2.0.0-beta

2.0.0-beta

EPSS

Процентиль: 8%
0.00031
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
5 месяцев назад

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

CVSS3: 6.1
redhat
5 месяцев назад

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

CVSS3: 6.1
nvd
5 месяцев назад

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

CVSS3: 6.1
debian
5 месяцев назад

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-sit ...

EPSS

Процентиль: 8%
0.00031
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79