{"id":"GHSA-qvqv-mcxr-x8qw","summary":"Slim Select has potential Cross-site Scripting issue","details":"Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation. Software that depends on this library to dynamically generate lists using unsanitized user-provided input may be vulnerable to cross-site scripting, resulting in attacker executed JavaScript. This vulnerability is fixed in 2.9.2.","aliases":["CVE-2024-9440"],"modified":"2024-10-18T15:03:40Z","published":"2024-10-02T21:30:34Z","database_specific":{"nvd_published_at":"2024-10-02T19:15:15Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-10-08T18:50:08Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9440"},{"type":"WEB","url":"https://github.com/brianvoe/slim-select/issues/564"},{"type":"WEB","url":"https://github.com/brianvoe/slim-select/pull/572"},{"type":"WEB","url":"https://github.com/brianvoe/slim-select/commit/f8534f27d6e9bab89024d139f1c4f7555f1efd5e"},{"type":"PACKAGE","url":"https://github.com/brianvoe/slim-select"},{"type":"WEB","url":"https://github.com/brianvoe/slim-select/blob/e7e37e2ff90e125f846bd98d6b8f278524ead79e/src/slim-select/select.ts#L377"},{"type":"WEB","url":"https://vulncheck.com/advisories/slim-select-xss"}],"affected":[{"package":{"name":"slim-select","ecosystem":"npm","purl":"pkg:npm/slim-select"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.9.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-qvqv-mcxr-x8qw/GHSA-qvqv-mcxr-x8qw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}