Description
Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XSS) bug. We recommend upgrading to version 0.0.20 of the extension.
Remediation
References
https://github.com/GoogleChromeLabs/critters/security/advisories/GHSA-cx3j-qqxj-9597
Related Vulnerabilities
CVE-2018-8038 Vulnerability in maven package org.apache.cxf.fediz:fediz-core
CVE-2023-38493 Vulnerability in maven package com.linecorp.armeria:armeria
CVE-2014-3709 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2023-23936 Vulnerability in npm package undici
CVE-2022-23618 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore