Advisories for Npm/Bootstrap-Vue package

2020

Cross-Site Scripting in bootstrap-vue

Versions of bootstrap-vue are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization, components may be vulnerable to Cross-Site Scripting through the options variable. This may lead to the execution of malicious JavaScript on the user's browser.