Versions of @berslucas/liljs prior to 1.0.2 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe innerHTML function without sanitizing input, which may allow attackers to execute arbitrary JavaScript on the victim's browser.
Upgrade to version 1.0.2 or later.
{
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:44:14Z",
"nvd_published_at": null,
"severity": "MODERATE",
"cwe_ids": [
"CWE-79"
]
}