Critters version 0.0.17-0.0.19 have an issue when parsing the HTML which leads to a potential cross-site scripting (XSS) bug.
The bug has been fixed in v0.0.20
.
Upgrading Critters version to >0.0.20
is the easiest fix. This is a non breaking version upgrade so we recommend all users to use v0.0.20
.
{ "github_reviewed_at": "2023-08-11T18:57:53Z", "cwe_ids": [ "CWE-116", "CWE-79", "CWE-80" ], "nvd_published_at": "2023-08-21T11:15:07Z", "severity": "MODERATE", "github_reviewed": true }