Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2023-37914 Vulnerability in maven package org.xwiki.platform:xwiki-platform-invitation-ui
CVE-2021-41862 Vulnerability in maven package com.googlecode.aviator:aviator
CVE-2020-28439 Vulnerability in npm package corenlp-js-prefab
CVE-2011-2204 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-29247 Vulnerability in maven package org.webjars.npm:electron