logo

GHSA-cx7r-634m-2q2h harp

Package

Manager: npm
Name: harp
Vulnerable Version: <0

Severity

Level: Medium

CVSS v3.1: N/A

CVSS v4.0: N/A

EPSS: N/A pctlN/A

Details

Cross-Site Scripting in harp # Withdrawn This advisory has been withdrawn per request from the maintainer. Given harp is a static webserver, a XSS type of vulnerability is not appropriate. ### Original advisory description All versions of `harp` are vulnerable to Cross-Site Scripting. Due to misconfiguration of its rendering engine, `harp` does not sanitize the HTML output allowing attackers to run arbitrary JavaScript when processing malicious files. ## Recommendation No fix is currently available. Consider using an alternative module until a fix is made available.

Metadata

Created: 2020-09-02T18:20:21Z
Modified: 2021-06-01T22:21:08Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-cx7r-634m-2q2h/GHSA-cx7r-634m-2q2h.json
CWE IDs: []
Alternative ID: N/A
Finding: N/A
Auto approve: 0