Vulnerabilities/

Cross-Site Scripting in backbone

Severity:
Medium

Description

Affected versions of backbone are vulnerable to cross-site scripting when users are allowed to supply input to the Model#Escape function, and the output is then written to the DOM.

The vulnerability occurs as a result of the regular expression used to encode metacharacters failing to take HTML Entities such as < into account.

Recommendation

Update the backbone package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
backbone
Anything's wrong? Let us know Last updated on January 16, 2026