Skip to content

Cross-Site Scripting in node-red

Moderate severity GitHub Reviewed Published Jan 30, 2020 • Updated Aug 13, 2022

Package

npm node-red (npm)

Affected versions

<= 0.20.7

Patched versions

0.20.8

Description

Versions of node-red prior to 0.20.8are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize the name field in new Flows, allowing attackers to execute arbitrary JavaScript in the victim's browser.

Recommendation

Upgrade to version 0.18.6 or later.

References

Severity

Moderate

Weaknesses

CVE ID

CVE-2019-15607

GHSA ID

GHSA-8w65-xjc5-9w79

Source code

No known source code
Checking history
See something to contribute? Suggest improvements for this vulnerability.