Vulnerabilities/

Cross-Site Scripting in webtorrent

Severity:
Medium

Description

Versions of webtorrent prior to 0.107.6 are vulnerable to Cross-Site Scripting. webtorrent servers started with torrent.createServer() lists a torrent’s title and files in the index page without sanitization. This allows attackers to execute arbitrary JavaScript in the victim’s browser through files with names containing the malicious payload.

Recommendation

Update the webtorrent package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
webtorrent
Anything's wrong? Let us know Last updated on April 04, 2023

This issue is available in SmartScanner Professional

See Pricing