Versions of selectize-plugin-a11y prior to 1.1.0 are vulnerable to Cross-Site Scripting. The accessibility.liveRegion.speak function does not sanitize the msg variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser.
// recommendation
Upgrade to version 1.1.0 or later.
// cvss v3.0 vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Checked 2026-10-04 at 01:10 UTC. The most recent advisory here was published 2019-08-27. Updated continuously from NVD, GHSA, OSV and CNA feeds.