Skip to content

Resolved 1/2 "Unsafe HTML construction in leaflet library input"

Choose a tag to compare

@Stassi Stassi released this 05 Oct 07:14
· 430 commits to main since this release

Changelog: v0.0.33...v0.0.34
Pull request: #34
Partially resolves potential vulnerability (1 of 2): Unsafe HTML construction in leaflet library input

Partial resolution to potential vulnerability (1 of 2)

The leaflet library was found constructing HTML dynamically based on potentially unsafe input, which could allow attackers to inject untrusted HTML or scripts into the web page, leading to a cross-site scripting (XSS) vulnerability.

View the full security disclosure at the project's security policy document.

Solution (partial)

innerHTML attribute mutations in leaflet are sanitized at build time with DOMPurify.sanitize(...) wrappers, partially resolving the potential vulnerability.

Update required

If any project requires a version of @stassi/leaflet prior to v0.0.34, run npm update immediately to ensure the latest security updates are received.