{"id":"GHSA-c7pp-g2v2-2766","summary":"DOM-based XSS in gmail-js","details":"Affected versions of `gmail-js` are vulnerable to cross-site scripting in the `tools.parse_response`, `helper.get.visible_emails_post`, and `helper.get.email_data_post` functions, which pass user input directly into the Function constructor.\n\n\n\n## Recommendation\n\nUpdate to version 0.6.5 or later.","aliases":["CVE-2016-1000228"],"modified":"2023-11-08T03:58:07.661328Z","published":"2020-09-01T15:32:04Z","database_specific":{"github_reviewed_at":"2020-08-31T18:11:40Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000228"},{"type":"WEB","url":"https://github.com/KartikTalwar/gmail.js/issues/281"},{"type":"WEB","url":"https://github.com/KartikTalwar/gmail.js/commit/a83436f499f9c01b04280af945a5a81137b6baf1"},{"type":"PACKAGE","url":"https://github.com/KartikTalwar/gmail.js"},{"type":"WEB","url":"https://www.npmjs.com/advisories/125"}],"affected":[{"package":{"name":"gmail-js","ecosystem":"npm","purl":"pkg:npm/gmail-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.6.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-c7pp-g2v2-2766/GHSA-c7pp-g2v2-2766.json"}}],"schema_version":"1.9.0"}