{"id":"GHSA-w4vp-3mq7-7v82","summary":"Cross-Site Scripting in lazysizes","details":"Versions of `lazysizes` prior to 5.2.1-rc1 are vulnerable to Cross-Site Scripting.  The `video-embed` plugin fails to sanitize the following attributes: data-vimeo, `data-vimeoparams`, `data-youtube` and `data-ytparams`. This allows attackers to execute arbitrary JavaScript in a victim's browser if the attacker has control over the vulnerable attributes.\n\n\n## Recommendation\n\nUpgrade to version 5.2.1-rc1 or later.","modified":"2020-08-31T19:01:17Z","published":"2020-09-03T15:49:48Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-08-31T19:01:17Z"},"references":[{"type":"WEB","url":"https://github.com/aFarkas/lazysizes/issues/764"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1493"}],"affected":[{"package":{"name":"lazysizes","ecosystem":"npm","purl":"pkg:npm/lazysizes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.2.1-rc1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 5.2.1-rc0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-w4vp-3mq7-7v82/GHSA-w4vp-3mq7-7v82.json"}}],"schema_version":"1.9.0"}