monocart-code-viewer is vulnerable to Cross-Site Scripting (XSS)
70
High Risk
Affected versions of this package are vulnerable to cross-site scripting (XSS) because untrusted input was previously written to the DOM using innerHTML, allowing attacker-controlled HTML or script-capable markup to be interpreted by the browser. This issue was fixed by replacing innerHTML with textContent, which renders the input as plain text instead of executable markup. An attacker might exploit this by supplying crafted input that injects malicious script or event handlers into the page, potentially leading to session theft, account takeover, or unauthorized actions in the victim’s browser.
You are affected if you are using a version that falls within the vulnerable range.
monocart-code-viewer is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 1.1.5.
Upgrade the monocart-code-viewer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant