This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2021-04-21T18:19:08Z",
"nvd_published_at": "2020-10-20T11:15:00Z"
}