ammonia is vulnerable to Cross-Site Scripting (XSS)
40
Medium Risk
Affected versions of this package are vulnerable to a mutation cross-site scripting (mXSS), which arises when DOM cleanup operations inadvertently cause namespace changes, potentially reintroducing malicious elements or attributes that bypass sanitization. This vulnerability allows an attacker to exploit it by crafting input that triggers these namespace switches during processing, leading to the execution of arbitrary JavaScript in the user's context.
You are affected if you are using a version that falls within the vulnerable range.
ammonia is vulnerable to Cross-Site Scripting (XSS) in versions 4.1.0 - 4.1.1, 4.0.0 - 4.0.0 and 3.0.0 - 3.3.0.
Upgrade the ammonia library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant