Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2020-28168 Vulnerability in maven package org.webjars.bowergithub.axios:axios
CVE-2022-24377 Vulnerability in npm package cycle-import-check
CVE-2022-29229 Vulnerability in npm package cassproject
CVE-2021-36373 Vulnerability in maven package org.apache.ant:ant
CVE-2022-1291 Vulnerability in maven package org.webjars.npm:tableexport.jquery.plugin