Vulnerabilities/

Cross-Site Scripting in swagger-ui (GHSA-mrx7-8hxf-f853)

Severity:
High

Description

Affected versions of swagger-ui are vulnerable to cross-site scripting. This vulnerability exists because swagger-ui automatically executes external Javascript that is loaded in via the url query string parameter when a Content-Type: application/javascript header is included.

Recommendation

Update the swagger-ui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
swagger-ui
Anything's wrong? Let us know Last updated on October 10, 2023

This issue is available in SmartScanner Professional

See Pricing