@openlist-frontend/openlist-frontend@4.0.0-rc.1 vulnerabilities

A new AList Fork to Anti Trust Crisis

Direct Vulnerabilities

Known vulnerabilities in the @openlist-frontend/openlist-frontend package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

@openlist-frontend/openlist-frontend is an A new AList Fork to Anti Trust Crisis

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the Markdown Viewer when rendering .py files containing <script> tags. An attacker can access sensitive user information, such as cookies and localStorage data, by tricking users into viewing a maliciously crafted file in preview or browsing mode.

Note:

This is only exploitable if the user manually switches to the affected mode and the file is encoded with ISO-8859-1.

How to fix Cross-site Scripting (XSS)?

Upgrade @openlist-frontend/openlist-frontend to version 4.0.0-rc.4 or higher.

<4.0.0-rc.4