validator is vulnerable to Cross-Site Scripting (XSS)
43
Medium Risk
Affected versions of this package are vulnerable to Cross-Site Scripting due to a URL Validation Bypass using URL Encoding, where the isURL function fails to properly validate URLs containing URL-encoded characters. It allows attackers to craft URLs that evade validation checks, and by tricking users into clicking such links, they can execute arbitrary JavaScript in the victim's browser, leading to cross-site scripting (XSS) attacks and potential compromise of user data or session hijacking.
You are affected if you are using a version that falls within the vulnerable range.
validator is vulnerable to Cross-Site Scripting (XSS) in versions 5.0.0 - 13.15.25.
Upgrade the validator library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant