Prototype Pollution In express-xss-sanitizer

Description

express-xss-sanitizer vulnerable to Prototype Pollution via allowedTags attribute The package express-xss-sanitizer before 1.1.3 is vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions