Vulnerabilities/

Cross site scripting in three.js

Severity:
High

Description

Versions of three.js prior to 0.137.0 load untrusted iframes and allow for attackers to inject arbitrary javascript into a users browser.

Recommendation

Update the three package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
three
Anything's wrong? Let us know Last updated on February 03, 2023

This issue is available in SmartScanner Professional

See Pricing