{"id":"GHSA-5726-g6r9-5f22","summary":"Potential for Script Injection in syntax-error","details":"Versions of `syntax-error` prior to 1.1.1 are affected by a cross-site scripting vulnerability which may allow a malicious file to execute code when browserified. \n\n## Recommendation\n\nUpdate to version 1.1.1 or later.","aliases":["CVE-2014-7192"],"modified":"2023-11-08T03:57:44.554728Z","published":"2017-10-24T18:33:36Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:00:12Z","nvd_published_at":null,"cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-7192"},{"type":"WEB","url":"https://github.com/substack/node-syntax-error/commit/9aa4e66eb90ec595d2dba55e6f9c2dd9a668b309"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96728"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5726-g6r9-5f22"},{"type":"WEB","url":"https://github.com/substack/node-browserify/blob/master/changelog.markdown#421"},{"type":"PACKAGE","url":"https://github.com/substack/node-syntax-error"},{"type":"WEB","url":"https://www.npmjs.com/advisories/37"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21690815"}],"affected":[{"package":{"name":"syntax-error","ecosystem":"npm","purl":"pkg:npm/syntax-error"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-5726-g6r9-5f22/GHSA-5726-g6r9-5f22.json"}}],"schema_version":"1.9.0"}