@boxyhq/saml-jackson is vulnerable to Cross-Site Scripting (XSS)
88
High Risk
A DOM-based Cross-Site Scripting (XSS) vulnerability was identified in Ory Polis’s login flow. The application incorrectly trusts the callbackUrl parameter and passes it to router.push, allowing an attacker to craft a malicious link that triggers a client-side redirect and executes arbitrary JavaScript in the victim’s browser. If opened by an authenticated user, or by a user who logs in afterward, this could enable session or credential theft, unauthorized actions in the user’s context, and potential internal network abuse.
You are affected if you are using a version that falls within the vulnerable range.
@boxyhq/saml-jackson is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 1.52.2.
Upgrade the @boxyhq/saml-jackson library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant