Description
verdaccio before 3.12.0 allows XSS.
Remediation
References
https://github.com/verdaccio/verdaccio/security/advisories/GHSA-78j5-gcmf-vqc8
Related Vulnerabilities
CVE-2019-1010266 Vulnerability in maven package org.webjars.npm:lodash
CVE-2022-25847 Vulnerability in npm package serve-lite
CVE-2023-26488 Vulnerability in npm package @openzeppelin/contracts
CVE-2020-7760 Vulnerability in maven package org.webjars.npm:codemirror
CVE-2022-38370 Vulnerability in maven package org.apache.iotdb:iotdb-grafana-connector