CVE-2021-23447

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in npm/teddy

Identifiers

CVE-2021-23447

Package Slug

npm/teddy

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).

Affected Versions

All versions before 0.5.9

Solution

Upgrade to version 0.5.9 or above.

Last Modified

2021-10-18

source