Intel

AIKIDO-2025-10114

@contentstack/utils is vulnerable to Improper Neutralization of Script-Related HTML Tags

Improper Neutralization of Script-Related HTML Tags Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 26, 2025

50

Medium Risk

This Affects:

JS@contentstack/utils
1.0.0 - 1.3.18
Fixed in 1.3.19
Are you affected? Scan for Free

TL;DR

Affected versions of @contentstack/utils are vulnerable to HTML injection in attribute keys and values. An attacker can inject malicious HTML, potentially leading to unintended behavior or further exploitation, depending on how the injected content is processed.

Who does this affect?

You are affected if you use a vulnerable version of craft-retour.

Background info

@contentstack/utils is vulnerable to Improper Neutralization of Script-Related HTML Tags in versions 1.0.0 - 1.3.18.

How to fix this

Upgrade @contentstack/utils to the patch version.