datacontract-cli is vulnerable to Cross-Site Scripting (XSS)
54
Medium Risk
datacontract export html and datacontract catalog render data contract field values into Jinja HTML without reliably escaping them, and Mermaid diagram names from model/field/type strings are embedded in a | safe <pre class="mermaid"> block after only light sanitization. An attacker who can influence contract content can inject HTML or script that runs when a victim opens the generated HTML or catalog page. The fix enables proper Jinja autoescape for HTML templates and strips HTML-unsafe characters from Mermaid names before they are embedded.
You are affected if you are using a version that falls within the vulnerable range and you export HTML or generate a catalog from data contracts that may contain untrusted field values.
datacontract-cli is vulnerable to Cross-Site Scripting (XSS) in versions 0.10.2 - 1.1.1.
Upgrade the datacontract-cli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.