Description
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.
Remediation
References
https://github.com/guardian/html-janitor/issues/35
https://hackerone.com/reports/308158
Related Vulnerabilities
CVE-2018-20676 Vulnerability in npm package bootstrap-sass
CVE-2023-24621 Vulnerability in maven package com.esotericsoftware.yamlbeans:yamlbeans
CVE-2020-6427 Vulnerability in npm package electron
CVE-2019-16557 Vulnerability in maven package com.redgate.plugins.redgatesqlci:redgate-sql-ci
CVE-2020-7784 Vulnerability in npm package ts-process-promises