GHSA-w4v7-hwx7-9929
MODERATECVE-2021-23784This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.
- Affected
- < 0.4.0
- Fixed in
- 0.4.0
- Published
- 2021-11-08
- Source
- github