Description
Versions of selectize-plugin-a11y
prior to 1.1.0 are vulnerable to Cross-Site Scripting. The accessibility.liveRegion.speak
function does not sanitize the msg
variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim’s browser.
Recommendation
Update the selectize-plugin-a11y
package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.1.0
- Patched version(s): 1.1.0
References
Related Issues
- counterpart vulnerable to prototype pollution - CVE-2025-57354
- Parse Server has an OAuth login vulnerability - CVE-2025-30168
- Use of Insufficiently Random Values in undici - CVE-2025-22150
- SummerNote Cross Site Scripting Vulnerability - CVE-2024-37629
- Tags:
- npm
- selectize-plugin-a11y
Anything's wrong? Let us know Last updated on January 09, 2023