@taquito/taquito is vulnerable to Cross-Site Scripting (XSS)
46
Medium Risk
Affected versions of this package contain a Cross-Site Scripting (XSS) vulnerability in the search results rendering function due to unsafely setting innerHTML with user-controlled data from r.item.title or r.item.excerpt. An attacker could exploit this by crafting a malicious search entry where the title or excerpt contains a script payload. When the results are displayed, this payload would be injected into the DOM and executed in the victim's browser, potentially compromising their session.
You are affected if you are using a version that falls within the vulnerable range.
@taquito/taquito is vulnerable to Cross-Site Scripting (XSS) in versions 24.0.0 - 24.0.1.
Upgrade the @taquito/taquito library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant