Description
All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule @keyframes.
This package is depended on by react-letter, therefore everyone using react-letter is also at risk.
Recommendation
Update the lettersanitizer package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.2
- Patched version(s): 1.0.2
References
Related Issues
- Improper handling of multiline messages in node-irc affects matrix-appservice-irc - CVE-2022-29166
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- Possible inject arbitrary `CSS` into the generated graph affecting the container HTML - CVE-2022-31108
- Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation - CVE-2019-11004
You might also like:
- Tags:
- npm
- lettersanitizer
Anything's wrong? Let us know Last updated on January 27, 2023


