Versions of swagger-ui prior to 3.18.0 are vulnerable to Reverse Tabnapping. The package uses target='_blank' in anchor tags, allowing attackers to access window.opener for the original page. This is commonly used for phishing attacks.
Upgrade to version 3.18.0 or later.
{
"github_reviewed": true,
"github_reviewed_at": "2019-06-20T14:13:56Z",
"severity": "MODERATE",
"nvd_published_at": null,
"cwe_ids": [
"CWE-1022"
]
}