1.0.0
9 years ago
8 years ago
Known vulnerabilities in the hexo-editor package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
hexo-editor is a web editor for hexo. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to an enabled node integration. If the victim is tricked into pasting such code or open a crafted file in the markdown editor, the attacker will be able to steal user’s data from the computer or perform any actions on the machine that the application running on. How to fix Cross-site Scripting (XSS)? There is no fixed version for | * |