Vulnerabilities/

Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript

Severity:
Medium

Description

Versions of pannellum prior to 2.5.6 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize URLs for data URIs, which may allow attackers to execute arbitrary code in a victim’s browser.

Recommendation

Update the pannellum package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
pannellum
Anything's wrong? Let us know Last updated on January 11, 2023