smoothie@1.33.0 vulnerabilities

Smoothie Charts: smooooooth JavaScript charts for realtime streaming data

  • latest version

    1.36.1

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    2 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the smoothie package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    smoothie is a Smoothie Charts: smooooooth JavaScript charts for realtime streaming data

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

    How to fix Cross-site Scripting (XSS)?

    Upgrade smoothie to version 1.36.1 or higher.

    >=1.31.0 <1.36.1