QID 983406
QID 983406: Nodejs (npm) Security Update for shout (GHSA-26q7-g57v-mxcp)
Affected versions of `shout` do not escape the `/topic` command in messages, and are therefore vulnerable to cross-site scripting.
## Recommendation
Update to version 0.50.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-26q7-g57v-mxcp for updates pertaining to this vulnerability.
Vendor References
- GHSA-26q7-g57v-mxcp -
github.com/advisories/GHSA-26q7-g57v-mxcp
CVEs related to QID 983406
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-26q7-g57v-mxcp | shout |
|