@stencil/core is vulnerable to CSS injection
7
Low Risk
Affected versions of this package present a security risk due to the use of innerHTML for injecting CSS into <style> elements in bootstrap-lazy.ts. Switching to textContent mitigates the risk of executing malicious scripts. This is considered a low-risk issue, as most browser extensions block such behavior by default.
You are affected by this flaw if you use a version >= 4.7.2 and = 4.12.2 of this package.
@stencil/core is vulnerable to CSS injection in versions 4.7.2 - 4.12.2.
To fix, upgrade to version 4.12.3 or above.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant