html inputs of type password recorded in plaintext when converted to text inputs
- Severity:
- Medium
Description
Highlight may record passwords on customer deployments when a password html input is switched to type="text" via a javascript “Show Password” button. This differs from the expected behavior which always obfuscates type="password" inputs.
Recommendation
Update the highlight.run package to the latest compatible version. Followings are version details:
- Affected version(s): < 6.0.0
- Patched version(s): 6.0.0
References
Related Issues
- jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label - CVE-2022-31160
- angular vulnerable to regular expression denial of service via the <input type="url"> element - CVE-2023-26118
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE - CVE-2025-64495
- md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed) - CVE-2026-46492
You might also like:
- Tags:
- npm
- highlight.run
Anything's wrong? Let us know Last updated on November 08, 2023


