{"id":"GHSA-7p6w-x2gr-rrf8","summary":"ag-grid Cross-Site Scripting vulnerability","details":"Versions of `ag-grid` prior to 14.0.0 are vulnerable to Cross-Site Scripting (XSS). Grid contents are not properly sanitized and may allow attackers to execute arbitrary JavaScript if user input is rendered in the grid. \n\n\n## Recommendation\n\nUpgrade to version 14.0.0 or later.","modified":"2025-07-10T16:49:40Z","published":"2020-09-02T21:28:05Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:39:39Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/ag-grid/ag-grid/issues/1961"},{"type":"WEB","url":"https://github.com/github/advisory-database/issues/5799"},{"type":"WEB","url":"https://github.com/ag-grid/ag-grid/commit/b66b1ddf73056714f6574e054d6e05d6ba531ce8"},{"type":"PACKAGE","url":"https://github.com/ag-grid/ag-grid"}],"affected":[{"package":{"name":"ag-grid","ecosystem":"npm","purl":"pkg:npm/ag-grid"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"14.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-7p6w-x2gr-rrf8/GHSA-7p6w-x2gr-rrf8.json"}}],"schema_version":"1.9.0"}