sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
| Software | From | Fixed in |
|---|---|---|
| paypal / braintree/sanitize-url | - | 6.0.2 |
@braintree / sanitize-url
|
- | 6.0.1 |