{"id":"GHSA-g9wg-wq4f-2x5w","aliases":[],"url":"https://o3.security/vulnerability/GHSA-g9wg-wq4f-2x5w","summary":"Cross-Site Scripting in console-feed","details":"Versions of `console-feed` prior to 2.8.10 are vulnerable to Cross-Site Scripting (XSS). The package fails to properly escape the rendered output. If an application uses `console-feed` and a malicious JavaScript payload was passed to a `console.log('%_', payload)` call, the package would render HTML containing the malicious payload.\n\n\n## Recommendation\n\nUpgrade to version 2.8.10 or later.","published":"2020-09-03T19:00:10Z","modified":"2020-08-31T18:46:53Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"console-feed","fixedVersion":"2.8.10"}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1088"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:46:53Z"}}