Vulnerabilities/

Cross-site Scripting in sanitize-url

Severity:
Medium

Description

The package @braintree/sanitize-url before 6.0.0 is vulnerable to Cross-site Scripting (XSS) due to improper sanitization in the sanitizeUrl function.

Recommendation

Update the @braintree/sanitize-url package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@braintree/sanitize-url
Anything's wrong? Let us know Last updated on January 27, 2023