Description
TimelineJS renders some user data as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file.
Most TimelineJS users configure their timeline with a Google Sheets document.
Recommendation
Update the @knight-lab/timelinejs package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.7.0
- Patched version(s): 3.7.0
References
- GHSA-2jpm-827p-j44g
- knightlab.northwestern.edu
- CVE-2020-15092
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration - CVE-2026-34725
- @payloadcms/next has Stored XSS in Admin Panel - CVE-2026-34748
- Cross-site Scripting (XSS) in Eclipse Theia - CVE-2020-27224
- XSS in Vega - CVE-2020-26296
You might also like:
- Tags:
- npm
- @knight-lab/timelinejs
Anything's wrong? Let us know Last updated on January 09, 2023


