Intel

AIKIDO-2024-10096

@braintree/sanitize-url is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 20, 2024

50

Medium Risk

This Affects:

JS@braintree/sanitize-url
1.0.0 - 7.0.1
Fixed in 7.0.2
Are you affected? Scan for Free

TL;DR

Affected versions of the @braintree/sanitize-url library are vulnerable to Cross-site Scripting (XSS). When using this library to sanitize URLs, certain whitespace sequences are not properly escaped, which can lead to an XSS attack.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@braintree/sanitize-url is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 7.0.1.

How to fix this

Upgrade the @braintree/sanitize-url library to the patch version.