Vulnerabilities/

Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)

Severity:
High

Description

Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’) vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.

Recommendation

Update the linkifyjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
linkifyjs
Anything's wrong? Let us know Last updated on July 29, 2025

This issue is available in SmartScanner Professional

See Pricing