{"id":"GHSA-c53x-wwx2-pg96","summary":"Cross-Site Scripting in @berslucas/liljs","details":"Versions of  `@berslucas/liljs` prior to 1.0.2 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe `innerHTML` function without sanitizing input, which may allow attackers to execute arbitrary JavaScript on the victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 1.0.2 or later.","modified":"2021-09-28T17:27:43Z","published":"2020-09-03T17:03:58Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:44:14Z"},"references":[{"type":"WEB","url":"https://github.com/bersLucas/liljs/pull/7"},{"type":"WEB","url":"https://github.com/bersLucas/liljs/commit/779c0dcd8aba434a1c94db7d1d2d990a629f9a6c"},{"type":"PACKAGE","url":"https://github.com/bersLucas/liljs"},{"type":"WEB","url":"https://github.com/bersLucas/liljs/releases/tag/1.0.2"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-BERSLUCASLILJS-450217"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1016"}],"affected":[{"package":{"name":"@berslucas/liljs","ecosystem":"npm","purl":"pkg:npm/%40berslucas/liljs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-c53x-wwx2-pg96/GHSA-c53x-wwx2-pg96.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}