GHSA-pxpf-v376-7xx5
MODERATECVE-2022-25854This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the cross-site scripting (XSS) payload.
- Affected
- < 4.9.8
- Fixed in
- 4.9.8
- Weakness
- CWE-79
- Published
- 2022-04-30
- Source
- github