Vulnerabilities/

Orejime has executable code in HTML attributes

Severity:
Low

Description

On HTML elements handled by Orejime, one could run malicious code by embedding javascript: code within data attributes. When consenting to the related purpose, Orejime would turn data attributes into unprefixed ones (i.e. data-href into href), thus executing the code.

Recommendation

Update the orejime package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
orejime
Anything's wrong? Let us know Last updated on January 13, 2026