Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2020-15366 Vulnerability in npm package ajv
CVE-2022-39382 Vulnerability in npm package @keystone-6/core
CVE-2021-21316 Vulnerability in npm package less-openui5
CVE-2022-36920 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2014-7191 Vulnerability in maven package org.webjars.bower:qs