Medium severity6.1NVD Advisory· Published May 31, 2018· Updated Jun 17, 2026
CVE-2016-10548
CVE-2016-10548
Description
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to the calc function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
reduce-css-calcnpm | < 1.2.5 | 1.2.5 |
Affected products
3- cpe:2.3:a:reduce-css-calc_project:reduce-css-calc:*:*:*:*:*:node.js:*:*Range: <=1.2.4
- HackerOne/reduce-css-calc node modulev5Range: <=1.2.4
Patches
Vulnerability mechanics
References
5- gist.github.com/ChALkeR/415a41b561ebea9b341efbb40b802fc9nvdExploitThird Party AdvisoryWEB
- nodesecurity.io/advisories/144nvdExploitThird Party Advisory
- github.com/advisories/GHSA-4662-j96g-mv46ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-10548ghsaADVISORY
- www.npmjs.com/advisories/144ghsaWEB
News mentions
0No linked articles in our index yet.