Vulnerabilities/

Read the Docs vulnerable to Cross-Site Scripting (XSS)

Severity:
Medium

Description

This vulnerability allowed a malicious user to serve arbitrary HTML files from the main application domain (readthedocs[.]org/readthedocs[.]com) by exploiting a vulnerability in the code that serves downloadable content from a project.

Recommendation

Update the readthedocs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
readthedocs
Anything's wrong? Let us know Last updated on January 07, 2023