{"id":"GHSA-j6p2-cx3w-6jcp","summary":"Cross-Site Scripting in backbone","details":"Affected versions of `backbone` are vulnerable to cross-site scripting when users are allowed to supply input to the `Model#Escape` function, and the output is then written to the DOM. \n\nThe vulnerability occurs as a result of the regular expression used to encode metacharacters failing to take HTML Entities such as `&#60;` into account.\n\n\n## Recommendation\n\nUpdate to version 0.5.0 or later.","aliases":["CVE-2016-10537"],"modified":"2026-02-03T03:07:13.937421Z","published":"2019-02-18T23:39:55Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:42:17Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10537"},{"type":"WEB","url":"https://github.com/jashkenas/backbone/commit/0cdc525961d3fa98e810ffae6bcc8e3838e36d93"},{"type":"WEB","url":"https://github.com/jashkenas/backbone/commit/7ae0384120c2552e1c426cda7fb02fdce6ef1076"},{"type":"WEB","url":"https://backbonejs.org/#changelog"},{"type":"PACKAGE","url":"https://github.com/jashkenas/backbone"},{"type":"WEB","url":"https://github.com/jashkenas/backbone/blame/0cdc525961d3fa98e810ffae6bcc8e3838e36d93/backbone.js"},{"type":"WEB","url":"https://github.com/jashkenas/backbone/compare/0.3.3...0.5.0#diff-0d56d0d310de7ff18b3cef9c2f8f75dcL1008"}],"affected":[{"package":{"name":"backbone","ecosystem":"npm","purl":"pkg:npm/backbone"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.3.3"},{"fixed":"0.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-j6p2-cx3w-6jcp/GHSA-j6p2-cx3w-6jcp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}