The Nextcloud dialogs library (npm package @nextcloud/dialogs) before 3.1.2 insufficiently escaped text input passed to a toast. If your application displays toasts with user-supplied input, this could lead to a XSS vulnerability. The vulnerability has been patched in version 3.1.2 If you need to display HTML in the toast, explicitly pass the options.isHTML config flag.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:nextcloud\\/dialogs_project:nextcloud\\/dialogs:*:*:*:*:*:node.js:*:*"
],
"source": "CPE_RANGE",
"extracted_events": [
{
"fixed": "3.1.2"
}
],
"vendor_product": "nextcloud/dialogs_project:nextcloud/dialogs"
}
]
}