Advisories for Npm/Plotly.js package

2024
2017
2016

Cross Site Scripting

If an attacker can trick an unsuspecting user into viewing a specially crafted plot on a site that uses plotly.js, then the attacker could potentially retrieve authentication tokens and perform actions on behalf of the user.