Vulnerabilities/

dom-iterator code execution vulnerability

Severity:
Medium

Description

Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled.

Recommendation

Update the dom-iterator package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
dom-iterator
Anything's wrong? Let us know Last updated on January 14, 2025