redoc@0.15.3 vulnerabilities


Direct Vulnerabilities

Known vulnerabilities in the redoc package. This does not include vulnerabilities belonging to this package’s dependencies.

Cross-site Scripting (XSS)

redoc is an OpenAPI/Swagger-generated API Reference Documentation.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). valueToHTML in src/utils/jsonToHtml.ts does not sanitize provided URI values.

How to fix Cross-site Scripting (XSS)?

Upgrade redoc to version 2.0.0-rc.28 or higher.