Critters version 0.0.17-0.0.19 have an issue when parsing the HTML which leads to a potential cross-site scripting (XSS) bug.
The bug has been fixed in v0.0.20.
Upgrading Critters version to >0.0.20 is the easiest fix. This is a non breaking version upgrade so we recommend all users to use v0.0.20.
{
"github_reviewed_at": "2023-08-11T18:57:53Z",
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": "2023-08-21T11:15:07Z",
"cwe_ids": [
"CWE-116",
"CWE-79",
"CWE-80"
]
}