Vulnerabilities/

Cross-Site Scripting in Prism (GHSA-wvhm-4hhf-97x9)

Severity:
High

Description

The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer.

This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the Previewers plugin (>=v1.10.0) or the Previewer: Easing plugin (v1.1.0 to v1.9.0).

Recommendation

Update the prismjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
prismjs
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing