@ionic/core@0.0.2-16 vulnerabilities

Base components for Ionic

Direct Vulnerabilities

Known vulnerabilities in the @ionic/core package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Cross-site Scripting (XSS)

@ionic/core is a the open-source mobile app development framework that makes it easy to build top quality native and progressive web apps with web technologies.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the following components:


This is due to improper sanitising of innerHTML.

How to fix Cross-site Scripting (XSS)?

Upgrade @ionic/core to version 4.0.3, 4.1.3, 4.2.1, 4.3.1 or higher.

<4.0.3 >=4.1.0 <4.1.3 >=4.2.0 <4.2.1 >=4.3.0 <4.3.1