Server side template injection In typed-function
Description
Arbitrary JavaScript Execution in typed-function
Versions of typed-function prior to 0.10.6 are vulnerable to Arbitrary JavaScript Execution. Function names are not properly sanitized and may allow an attacker to execute arbitrary code.
Recommendation
Upgrade to version 0.10.6 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 0.10.6 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.