{"id":"GHSA-w4vp-3mq7-7v82","aliases":[],"url":"https://o3.security/vulnerability/GHSA-w4vp-3mq7-7v82","summary":"Cross-Site Scripting in lazysizes","details":"Versions of `lazysizes` prior to 5.2.1-rc1 are vulnerable to Cross-Site Scripting.  The `video-embed` plugin fails to sanitize the following attributes: data-vimeo, `data-vimeoparams`, `data-youtube` and `data-ytparams`. This allows attackers to execute arbitrary JavaScript in a victim's browser if the attacker has control over the vulnerable attributes.\n\n\n## Recommendation\n\nUpgrade to version 5.2.1-rc1 or later.","published":"2020-09-03T15:49:48Z","modified":"2020-08-31T19:01:17Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"lazysizes","fixedVersion":"5.2.1-rc1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/aFarkas/lazysizes/issues/764"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1493"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T19:01:17Z"}}