CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities.
This is patched in v1.14.0.
Users can apply encoding manually to their selectors, if they are unable to upgrade.
{
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed_at": "2025-05-28T16:06:03Z",
"github_reviewed": true,
"nvd_published_at": "2025-05-30T19:15:29Z"
}