CVE-2021-23447
npm/teddy
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).
All versions before 0.5.9
Upgrade to version 0.5.9 or above.
2021-10-18
source |