Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2022-24066 Vulnerability in npm package simple-git
CVE-2023-37259 Vulnerability in npm package matrix-react-sdk
CVE-2017-1000452 Vulnerability in npm package samlify
CVE-2022-24847 Vulnerability in maven package org.geoserver:gs-main
CVE-2020-35202 Vulnerability in maven package org.igniterealtime.openfire.plugins:dbaccess