spatie/schema-org is vulnerable to Cross-site Scripting (XSS)
50
Medium Risk
Improper neutralization of user-controlled data in toScript() output in spatie/schema-org allowed HTML script-tag breakout when attacker-supplied values were embedded in JSON-LD metadata. Because <script type="application/ld+json"> blocks were generated without escaping HTML tag delimiters, crafted input containing </script> sequences could inject executable JavaScript into the page. Successful exploitation could result in stored or reflected cross-site scripting.
You are affected if you are using a version that falls within the vulnerable range.
spatie/schema-org is vulnerable to Cross-site Scripting (XSS) in versions 3.23.1 - 4.0.1.
Upgrade the spatie/schema-org library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant