@lwc/shared is vulnerable to Cross-site Scripting (XSS)
20
Low Risk
Affected versions of the package allow Cross-site Scripting (XSS). Setting innerHTML outside of lwc:inner-html is possible, which becomes a vulnerability if a proper sanitizing hook is not used.
You are affected if you are using a version that falls within the vulnerable range.
@lwc/shared is vulnerable to Cross-site Scripting (XSS) in versions 2.5.0 - 8.1.1.
Upgrade the @lwc/shared library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant