bootstrap5-toggle is vulnerable to Cross-site Scripting (XSS)
44
Medium Risk
Affected versions of bootstrap5-toggle are vulnerable to cross-site scripting (xss) due to insufficient sanitization of HTML used in toggle labels. The component allows HTML content to be provided for the on/off labels, which was previously inserted into the DOM without proper filtering. An attacker who can control these label values could inject malicious HTML or JavaScript that executes in the context of the application. The issue is addressed by introducing HTML sanitization with an allow-list, ensuring that only safe markup is rendered in toggle labels.
You are affected if you are using a version that falls within the vulnerable range.
bootstrap5-toggle is vulnerable to Cross-site Scripting (XSS) in versions 5.0.0 - 5.2.0.
Upgrade the bootstrap5-toggle library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant