Medium severity5.4NVD Advisory· Published May 31, 2018· Updated Jun 17, 2026
CVE-2016-10537
CVE-2016-10537
Description
backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your RESTful API through JSON There exists a potential Cross Site Scripting vulnerability in the Model#Escape function of backbone 0.3.3 and earlier, if a user is able to supply input. This is due to the regex that's replacing things to miss the conversion of things such as < to <.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
backbonenpm | >= 0.3.3, < 0.5.0 | 0.5.0 |
Affected products
3- HackerOne/backbone node modulev5Range: <= 0.3.3
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-j6p2-cx3w-6jcpghsaADVISORY
- github.com/jashkenas/backbone/compare/0.3.3...0.5.0nvdIssue TrackingThird Party AdvisoryWEB
- nodesecurity.io/advisories/108nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2016-10537ghsaADVISORY
- backbonejs.orgghsaWEB
- github.com/jashkenas/backbone/commit/0cdc525961d3fa98e810ffae6bcc8e3838e36d93ghsaWEB
- github.com/jashkenas/backbone/commit/7ae0384120c2552e1c426cda7fb02fdce6ef1076ghsaWEB
News mentions
0No linked articles in our index yet.