Description
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
Recommendation
Update the valine package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.3.3
- Patched version(s): 1.3.4
References
Related Issues
- Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers - CVE-2026-27902
- Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes - CVE-2026-34405
- SCEditor has DOM XSS via emoticon URL/HTML injection - CVE-2026-25581
- Valine code injection vulnerability - CVE-2022-38545
You might also like:
- Tags:
- npm
- valine
Anything's wrong? Let us know Last updated on September 07, 2023


