{"id":"GHSA-588m-9qg5-35pq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-588m-9qg5-35pq","summary":"Reverse Tabnabbing in quill","details":"Versions of `quill` prior to 1.3.7 are vulnerable to [Reverse Tabnabbing](https://www.owasp.org/index.php/Reverse_Tabnabbing). The package uses `target='_blank'` in anchor tags, allowing attackers to access `window.opener` for the original page when opening links. This is commonly used for phishing attacks.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.","published":"2020-09-03T17:19:09Z","modified":"2021-09-28T22:06:18Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"quill","fixedVersion":"1.3.7"}],"fix":{"url":"https://github.com/quilljs/quill/pull/2674","label":"quilljs/quill#2674"},"references":[{"type":"WEB","url":"https://github.com/quilljs/quill/issues/2438"},{"type":"WEB","url":"https://github.com/quilljs/quill/pull/2674"},{"type":"PACKAGE","url":"https://github.com/quilljs/quill"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1039"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-28T22:06:18Z"}}