GMS-2020-761: Reverse Tabnabbing in quill
(updated )
Versions of quill
prior to 1.3.7 are vulnerable to Reverse Tabnabbing. The package uses target='_blank'
in anchor tags, allowing attackers to access window.opener
for the original page when opening links. This is commonly used for phishing attacks.
Recommendation
No fix is currently available. Consider using an alternative package until a fix is made available.
References
Detect and mitigate GMS-2020-761 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →