296,392
Total vulnerabilities in the database
Versions of node-red
prior to 0.18.6 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize the name
field in new items, allowing attackers to execute arbitrary JavaScript in the victim's browser.
Upgrade to version 0.18.6 or later.
Software | From | Fixed in |
---|---|---|
![]() |
- | 0.18.6 |