{"id":"GHSA-8fw4-xh83-3j6q","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8fw4-xh83-3j6q","summary":"Cross-Site Scripting in diagram-js","details":"Versions of `diagram-js` prior to 3.3.1 (for 3.x) and 2.6.2 (for 2.x) are vulnerable to Cross-Site Scripting. The package fails to escape output of user-controlled input in `search-pad`, allowing attackers to execute arbitrary JavaScript.\n\n\n## Recommendation\n\nIf you are using diagram-js 3.x, upgrade to version 3.3.1.\nIf you are using diagram-js 2.x, upgrade to version 2.6.2.","published":"2020-09-11T21:18:05Z","modified":"2021-09-28T16:58:42Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"diagram-js","fixedVersion":"2.6.2"},{"ecosystem":"npm","name":"diagram-js","fixedVersion":"3.3.1"}],"fix":{"url":"https://github.com/bpmn-io/diagram-js/commit/2565c40449379284a55163f290ec812db34244d1","label":"bpmn-io/diagram-js@2565c40"},"references":[{"type":"WEB","url":"https://github.com/bpmn-io/diagram-js/commit/2565c40449379284a55163f290ec812db34244d1"},{"type":"WEB","url":"https://github.com/bpmn-io/diagram-js/commit/777fa06d70036daa9d02f3be6d0732cf4ccd8d6d"},{"type":"WEB","url":"https://bpmn.io/blog/posts/2019-html-injection-vulnerabilities-fixed.html"},{"type":"PACKAGE","url":"https://github.com/bpmn-io/diagram-js"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-28T16:58:42Z"}}