albertoarena/laravel-truss is vulnerable to Cross-Site Scripting (XSS)
35
Low Risk
The HTML export embeds the database schema as JSON inside a <script type="application/json"> element, using json_encode() without JSON_HEX_TAG. A table name, index name, or column default that contains a literal </script> ends the script element early, so the browser processes the rest of the exported document as markup and the export looks truncated to the person who ran it. An attacker must already be able to set a hostile table name, index name, or column default in the database before the export runs. The fix adds JSON_HEX_TAG to the encoder so < and > in embedded values are escaped and cannot break out of the script element.
You are affected if you are using a version that falls within the vulnerable range and you use truss:export --format=html to export a schema that contains a table name, index name, or column default you do not fully control.
albertoarena/laravel-truss is vulnerable to Cross-Site Scripting (XSS) in versions 1.14.0 - 1.14.0.
Upgrade the albertoarena/laravel-truss library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.