Vulnerabilities/

Cross-Site Scripting in webpack-bundle-analyzer

Severity:
Medium

Description

Versions of webpack-bundle-analyzer prior to 3.3.2 are vulnerable to Cross-Site Scripting. The package uses JSON.stringify() without properly escaping input which may lead to Cross-Site Scripting.

Recommendation

Update the webpack-bundle-analyzer package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
webpack-bundle-analyzer
Anything's wrong? Let us know Last updated on April 13, 2023

This issue is available in SmartScanner Professional

See Pricing