← Voltar à pesquisa de CVEs

CVE-2026-42338

ip-address

Descrição

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error-s parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS 6.1EPSS 0.471%Risco 0.64
Ver fonte
Publicação
2026-05-12 20:16:41
Versões afetadas
<10.1.1
Tipo
Package
Última alteração
2026-08-10 13:19:28
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N