@amcharts/amcharts5 is vulnerable to Cross-Site Scripting (XSS)
59
Medium Risk
@amcharts/amcharts5 injects HTML-bearing content such as html and labelHTML settings, HTML tooltips, modal content, and export menu labels directly via innerHTML without sanitization. When an application renders attacker-influenced data through these sinks, embedded script or event-handler markup executes in the victim's browser. The fix adds an HTML sanitizer routed through all injection sinks.
You are affected if you are using a version that falls within the vulnerable range.
@amcharts/amcharts5 is vulnerable to Cross-Site Scripting (XSS) in versions 5.0.0 - 5.18.0.
Upgrade the @amcharts/amcharts5 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant