Description
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
Remediation
References
https://hackerone.com/reports/330356
Related Vulnerabilities
CVE-2020-8298 Vulnerability in npm package fs-path
CVE-2023-22491 Vulnerability in npm package gatsby-transformer-remark
CVE-2016-5018 Vulnerability in maven package org.apache.tomcat:jasper
CVE-2020-8823 Vulnerability in npm package sockjs
CVE-2021-39233 Vulnerability in maven package org.apache.ozone:ozone-main