{"id":"CVE-2021-32696","aliases":["GHSA-qxg5-2qff-p49r"],"url":"https://o3.security/vulnerability/CVE-2021-32696","summary":"Passing in a non-string 'html' argument can lead to unsanitized output","details":"The npm package \"striptags\" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array-like object is passed in as the `html` parameter. This can be abused by an attacker who can control the shape of their input, e.g. if query parameters are passed directly into the function. This can lead to a XSS.","published":"2021-06-18T20:15:07.633Z","modified":"2026-07-09T15:01:36.924832Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"striptags","fixedVersion":"3.2.0"}],"fix":{"url":"https://github.com/ericnorris/striptags/commit/f252a6b0819499cd65403707ebaf5cc925f2faca","label":"ericnorris/striptags@f252a6b"},"references":[{"type":"ADVISORY","url":"https://github.com/ericnorris/striptags/releases/tag/v3.2.0"},{"type":"ADVISORY","url":"https://github.com/ericnorris/striptags/security/advisories/GHSA-qxg5-2qff-p49r"},{"type":"ADVISORY","url":"https://www.npmjs.com/package/striptags"},{"type":"FIX","url":"https://github.com/ericnorris/striptags/commit/f252a6b0819499cd65403707ebaf5cc925f2faca"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T15:01:36.924832Z"}}