Vulnerabilities/

Stored Cross-site Scripting (XSS) in excalidraw's web embed component

Severity:
Medium

Description

A stored XSS vulnerability in Excalidraw’s web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor is hosted.

Recommendation

Update the @excalidraw/excalidraw package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@excalidraw/excalidraw
Anything's wrong? Let us know Last updated on April 18, 2024

This issue is available in SmartScanner Professional

See Pricing