{"id":"GHSA-8fw4-xh83-3j6q","summary":"Cross-Site Scripting in diagram-js","details":"Versions of `diagram-js` prior to 3.3.1 (for 3.x) and 2.6.2 (for 2.x) are vulnerable to Cross-Site Scripting. The package fails to escape output of user-controlled input in `search-pad`, allowing attackers to execute arbitrary JavaScript.\n\n\n## Recommendation\n\nIf you are using diagram-js 3.x, upgrade to version 3.3.1.\nIf you are using diagram-js 2.x, upgrade to version 2.6.2.","modified":"2021-09-28T16:58:42Z","published":"2020-09-11T21:18:05Z","database_specific":{"github_reviewed_at":"2020-08-31T18:42:58Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/bpmn-io/diagram-js/commit/2565c40449379284a55163f290ec812db34244d1"},{"type":"WEB","url":"https://github.com/bpmn-io/diagram-js/commit/777fa06d70036daa9d02f3be6d0732cf4ccd8d6d"},{"type":"WEB","url":"https://bpmn.io/blog/posts/2019-html-injection-vulnerabilities-fixed.html"},{"type":"PACKAGE","url":"https://github.com/bpmn-io/diagram-js"}],"affected":[{"package":{"name":"diagram-js","ecosystem":"npm","purl":"pkg:npm/diagram-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-8fw4-xh83-3j6q/GHSA-8fw4-xh83-3j6q.json"}},{"package":{"name":"diagram-js","ecosystem":"npm","purl":"pkg:npm/diagram-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-8fw4-xh83-3j6q/GHSA-8fw4-xh83-3j6q.json"}}],"schema_version":"1.9.0"}