@yaireo/tagify is vulnerable to Cross-site Scripting (XSS)
41
Medium Risk
Affected versions of this package are vulnerable to an XSS issue in tag content rendering, because HTML entities in tag text, title, and value are not properly escaped before insertion into the DOM. An attacker could craft tag values containing <, >, or " to inject and execute arbitrary HTML/JavaScript when the tag is rendered. The commit fixes this by escaping those characters in the tag text, title, and value properties before rendering to prevent malicious HTML injection.
You are affected if you are using a version that falls within the vulnerable range.
@yaireo/tagify is vulnerable to Cross-site Scripting (XSS) in versions 0.1.0 - 4.35.6.
Upgrade the @yaireo/tagify library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant