Advisories for Npm/Xmlhttprequest package

2021

Code Injection

Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.