Skip to content

Cross-Site Scripting in vant

High severity GitHub Reviewed Published Nov 22, 2019 to the GitHub Advisory Database • Updated Jan 9, 2023

Package

npm vant (npm)

Affected versions

< 2.1.8

Patched versions

2.1.8

Description

Versions of vant prior to 2.1.8 are vulnerable to Cross-Site Scripting. The text value of the Picker component column is not sanitized, which may allow attackers to execute arbitrary JavaScript in a victim's browser.

Recommendation

Upgrade to version 2.1.8 or later.

References

Reviewed Nov 21, 2019
Published to the GitHub Advisory Database Nov 22, 2019
Last updated Jan 9, 2023

Severity

High

Weaknesses

CVE ID

No known CVE

GHSA ID

GHSA-9xr8-8hmc-389f

Source code

No known source code
Checking history
See something to contribute? Suggest improvements for this vulnerability.