github.com
https://github.com/makeusabrew/bootbox GHSA-87MG-H5R3-HW88
Cross-Site Scripting in bootbox
Description
All version of `bootbox` are vulnerable to Cross-Site Scripting. The package does not sanitize user input in the provided dialog boxes, allowing attackers to inject HTML code and execute arbitrary JavaScript. ## Recommendation Sanitize user input being passed to `bootbox` or consider using an alternative package.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
bootboxBrowse npm / bootbox | GitHub Advisory | Through 5.5.2 | affected |
References
4github.com
https://github.com/makeusabrew/bootbox/issues/661 hackerone.com
https://hackerone.com/reports/508446 npmjs.com
https://www.npmjs.com/advisories/882