kreuzberg is vulnerable to Permissive Regular Expression
25
Low Risk
Affected versions of this package are vulnerable to injection attacks due to overly permissive regular expressions within the flag for stripping <script> and <style> tags. An attacker can exploit this by injecting a malformed tag where the inner, unclosed substring causes the regex to match too much or too little, allowing the malicious JavaScript payload to remain in the output and execute in a victim's browser.
You are affected if you are using a version that falls within the vulnerable range.
kreuzberg is vulnerable to Permissive Regular Expression in versions 3.0.0 - 3.21.0.
Upgrade the kreuzberg library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant