Vulnerabilities/

Improper handling of CSS at-rules in lettersanitizer

Severity:
High

Description

All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule @keyframes.

This package is depended on by react-letter, therefore everyone using react-letter is also at risk.

Recommendation

Update the lettersanitizer package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
lettersanitizer
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing