Versions of webpack-bundle-analyzer prior to 3.3.2 are vulnerable to Cross-Site Scripting. The package uses JSON.stringify() without properly escaping input which may lead to Cross-Site Scripting.
Upgrade to version 3.3.2 or later.
{
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2019-05-23T07:34:50Z",
"cwe_ids": [
"CWE-79"
],
"nvd_published_at": null
}