Description
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
Remediation
References
https://hackerone.com/reports/330356
Related Vulnerabilities
CVE-2021-23352 Vulnerability in npm package madge
CVE-2021-44684 Vulnerability in npm package github-todos
CVE-2021-32819 Vulnerability in npm package squirrelly
CVE-2023-31581 Vulnerability in maven package com.usthe.sureness:sureness-core
CVE-2022-41966 Vulnerability in maven package com.thoughtworks.xstream:xstream