smile/elasticsuite is vulnerable to Cross-Site Scripting (XSS)
70
High Risk
Affected versions of this package contain a Cross-Site Scripting (XSS) vulnerability in the layered navigation filter search, where user-supplied input is rendered without proper escaping, allowing arbitrary JavaScript execution in the browser. An attacker can exploit this by injecting malicious script payloads into the filter search field, leading to execution of attacker-controlled code in victims’ sessions. This may enable session hijacking, credential theft, or unauthorized actions performed on behalf of the user. The issue is caused by unsanitized rendering of search input, which was later fixed by properly escaping user input before display.
You are affected if you are using a version that falls within the vulnerable range.
smile/elasticsuite is vulnerable to Cross-Site Scripting (XSS) in versions 2.11.0.0 - 2.11.17.0 and 2.0.0.0 - 2.10.32.0.
Upgrade the smile/elasticsuite library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant