@boxyhq/saml-jackson is vulnerable to Cross-site Scripting (XSS)
30
Low Risk
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to insufficient validation of SSO URLs in the SAML metadata. An attacker can inject malicious scripts by manipulating these URLs, potentially compromising user sessions and security.
You are affected if you are using a version that falls within the vulnerable range.
@boxyhq/saml-jackson is vulnerable to Cross-site Scripting (XSS) in versions 1.3.0 - 1.43.0.
Upgrade the @boxyhq/saml-jackson library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant