Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2022-41927 Vulnerability in maven package org.xwiki.platform:xwiki-platform-tag-ui
CVE-2022-29770 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2020-28500 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2020-14195 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-36187 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind