CVE-2024-43796: express vulnerable to XSS via response.redirect()
(updated )
In express <4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect()
may execute untrusted code
References
Detect and mitigate CVE-2024-43796 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →