@vendure/dashboard is vulnerable to Cross-Site Scripting (XSS)
87
High Risk
The dashboard RichTextDescriptionCell strips HTML by assigning untrusted content to an element's innerHTML and reading back its textContent. Parsing the markup still triggers active handlers such as an img onerror, so a lower-privileged administrator can store a payload in a description field that executes when a higher-privileged administrator views the list. The fix parses the content with an inert parser that does not execute scripts or load resources.
You are affected if you are using a version that falls within the vulnerable range and administrators view entity description fields in the React dashboard.
@vendure/dashboard is vulnerable to Cross-Site Scripting (XSS) in versions 3.5.1 - 3.6.4.
Upgrade the @vendure/dashboard library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.