Medium severity6.1NVD Advisory· Published Jun 4, 2018· Updated Jun 17, 2026
CVE-2017-16022
CVE-2017-16022
Description
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:morris.js_project:morris.js:*:*:*:*:*:node.js:*:*Range: <=0.5.0
- ghsa-coords
- Range: <=0.5.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-fwx5-5fqj-jv98ghsaADVISORY
- github.com/morrisjs/morris.js/pull/464nvdThird Party AdvisoryWEB
- nodesecurity.io/advisories/307nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-16022ghsaADVISORY
- www.npmjs.com/advisories/307ghsaWEB
News mentions
0No linked articles in our index yet.