All versions of bracket-template are vulnerable to stored cross-site scripting (XSS). This is exploitable when a variable passed in via a GET parameter is used in a template.
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2019-05-30T21:02:27Z",
"nvd_published_at": null,
"severity": "HIGH"
}