← Späť na vyhľadávanie CVE

CVE-2026-42338

ip-address

Popis

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error-s parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS 6.1EPSS 0.471%Riziko 0.64
Zobraziť zdroj
Zverejnené
2026-05-12 20:16:41
Dotknuté verzie
<10.1.1
Typ
Package
Posledná úprava
2026-08-10 13:19:28
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N