Description
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.1.5
References
Related Issues
- Pandao editor.md vulnerable to XSS in IMG attributes - CVE-2018-16330
- Astro vulnerable to reflected XSS via the server islands feature - CVE-2025-64764
- MediaElement Vulnerable to Reflected XSS - CVE-2016-4567
- vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS) - CVE-2024-6783
- Tags:
- npm
- bracket-template
Anything's wrong? Let us know Last updated on September 11, 2023