{"id":"CVE-2022-21169","aliases":["GHSA-grjp-4jmr-mjcw"],"url":"https://o3.security/vulnerability/CVE-2022-21169","summary":"Prototype Pollution","details":"The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.","published":"2022-09-26T05:05:11.200Z","modified":"2026-07-15T01:48:51.347849747Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"express-xss-sanitizer","fixedVersion":"1.1.3"}],"fix":{"url":"https://github.com/AhmedAdelFahim/express-xss-sanitizer/commit/3bf8aaaf4dbb1c209dcb8d87a82711a54c1ab39a","label":"AhmedAdelFahim/express-xss-sanitizer@3bf8aaa"},"references":[{"type":"WEB","url":"https://runkit.com/embed/w306l6zfm7tu"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-EXPRESSXSSSANITIZER-3027443"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21169.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21169"},{"type":"REPORT","url":"https://github.com/AhmedAdelFahim/express-xss-sanitizer/issues/4"},{"type":"FIX","url":"https://github.com/AhmedAdelFahim/express-xss-sanitizer/commit/3bf8aaaf4dbb1c209dcb8d87a82711a54c1ab39a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:51.347849747Z"}}