QID 994885
Date Published: 2023-08-17
QID 994885: NodeJs (Npm) Security Update for @excalidraw/excalidraw (GHSA-v7v8-gjv7-ffmr)
XSS vulnerability due to improperly sanitizing URLs of links that can be attached on canvas elements. This affects users of the npm package @excalidraw/excalidraw provided it was deployed in environments where untrusted user input in drawings that are then shared with third parties is a concern. If you only hosted the editor in trusted environments, or sharing didn't take place, the impact is minimized.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v7v8-gjv7-ffmr for updates and patch information.
Vendor References
- GHSA-v7v8-gjv7-ffmr -
github.com/advisories/GHSA-v7v8-gjv7-ffmr
CVEs related to QID 994885
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v7v8-gjv7-ffmr | @excalidraw/excalidraw |
|