{"id":"GHSA-vvhj-v88f-5gxr","summary":"ghtml Cross-Site Scripting (XSS) vulnerability","details":"## Summary\n\nIt is possible to introduce user-controlled JavaScript code and trigger a Cross-Site Scripting (XSS) vulnerability in some cases.\n\n## Actions Taken\n\n- Updated the documentation to clarify that while `ghtml` escapes characters with special meaning in HTML, it does not provide comprehensive protection against all types of XSS attacks in every scenario. **_This aligns with the approach taken by other template engines. Developers should be cautious and take additional measures to sanitize user input and prevent potential vulnerabilities._** More reading: https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html\n- The backtick character (`) is now also escaped to prevent the creation of strings in most cases where a malicious actor somehow gains the ability to write JavaScript. This does not provide comprehensive protection either.","aliases":["CVE-2024-37166"],"modified":"2026-09-10T03:50:15.993061595Z","published":"2024-06-10T21:36:48Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-06-10T21:36:48Z","nvd_published_at":"2024-06-10T22:15:12Z","cwe_ids":["CWE-79","CWE-80"]},"references":[{"type":"WEB","url":"https://github.com/gurgunday/ghtml/security/advisories/GHSA-vvhj-v88f-5gxr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37166"},{"type":"WEB","url":"https://github.com/gurgunday/ghtml/commit/df1ea50fe8968a766fd2b9379a8f9806375227f8"},{"type":"PACKAGE","url":"https://github.com/gurgunday/ghtml"}],"affected":[{"package":{"name":"ghtml","ecosystem":"npm","purl":"pkg:npm/ghtml"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-vvhj-v88f-5gxr/GHSA-vvhj-v88f-5gxr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L"}]}