Advisories for Npm/Sockjs package

2020

Cross-Site Scripting

SockJS's function htmlfile in lib/transport/htmlfile.js is vulnerable to Reflected XSS via the /htmlfile endpoint through the c callback parameter.