Description
Versions of html-pages
before 2.1.0 are vulnerable to path traversal.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.1.2
References
- GHSA-fm87-46vv-jqrr
- hackerone.com
- www.npmjs.com
- CVE-2018-3744
- CWE-22
- CWE-35
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
Related Issues
- Denial of Service in jquery - CVE-2016-10707
- gifplayer XSS vulnerability - CVE-2025-31128
- Prototype pollution in gsap - CVE-2020-28478
- Cross-Site Scripting in html-pages - CVE-2018-16481
- Tags:
- npm
- html-pages
Anything's wrong? Let us know Last updated on January 31, 2023