@kolkov/angular-editor is vulnerable to Cross-Site Scripting (XSS)
66
Medium Risk
Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) via Unsafe Preview Rendering due to improper neutralization of user input during web page generation. The vulnerability exists because user-supplied HTML, including attributes like onerror, is rendered without adequate sanitization when switching from code to preview mode. An attacker can exploit this by tricking a user into submitting a malicious payload, which executes arbitrary JavaScript in the victim's browser when the preview is rendered.
You are affected if you are using a version that falls within the vulnerable range.
@kolkov/angular-editor is vulnerable to Cross-Site Scripting (XSS) in versions 2.2.0 - 3.0.3.
Upgrade the @kolkov/angular-editor library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant