Vulnerabilities/

jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin

Severity:
Medium

Description

Versions of jsondiffpatch prior to 0.7.2 are vulnerable to Cross-site Scripting (XSS) in the HtmlFormatter (HtmlFormatter::nodeBegin). When diffs are rendered to HTML using the built-in formatter, untrusted payloads can inject scripts and execute in the context of a consuming web page.

Affected versions: >= 0, < 0.7.

Recommendation

Update the jsondiffpatch package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jsondiffpatch
Anything's wrong? Let us know Last updated on September 22, 2025

This issue is available in SmartScanner Professional

See Pricing