Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade to plotly.js
version 1.16.0 or newer.
plotly.js
is a high-level, declarative charting library.
Affected versions of the package allowed the style attribute to be manipulated in the tag inside the embedded svg
making them vulnerable to a css injection which allowed for tracking images to be embedded and leak information to an external domain.
For more information, see Jared's post explaining the issue very well.