Description
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.
Recommendation
Update the ansi_up package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.0.0
- Patched version(s): 5.0.0
References
- GHSA-2v5f-23xc-v9qr
- doyensec.com
- security.netapp.com
- CVE-2021-3377
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- iziModal Cross-site Scripting vulnerability - CVE-2021-32860
- textAngular Cross-site Scripting vulnerability - CVE-2021-32854
- Mind-elixir Cross-site Scripting vulnerability - CVE-2021-32851
- Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags - CVE-2021-33295
You might also like:
- Tags:
- npm
- ansi_up
Anything's wrong? Let us know Last updated on November 04, 2025


