GHSA-rjjv-87mx-6x3h: @sveltejs/kit vulnerable to on dev mode 404 page
“Unsanitized input from the request URL flows into end, where it is used to render an HTML page returned to the user. This may result in a Cross-Site Scripting attack (XSS).”
References
Code Behaviors & Features
Detect and mitigate GHSA-rjjv-87mx-6x3h with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →