Vulnerabilities/

Smoothie vulnerable to Cross-site Scripting when tooltipLabel or strokeStyle are controlled by users

Severity:
Medium

Description

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

Recommendation

Update the smoothie package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
smoothie
Anything's wrong? Let us know Last updated on January 30, 2023