Medium severity6.1NVD Advisory· Published Jun 7, 2018· Updated Jun 17, 2026
CVE-2018-3735
CVE-2018-3735
Description
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bracket-templatenpm | <= 1.1.5 | — |
Affected products
3- HackerOne/bracket-template node modulev5Range: Versions up to and including 1.1.5
- cpe:2.3:a:bracket-template_project:bracket-template:*:*:*:*:*:node.js:*:*Range: <=1.1.5
Patches
Vulnerability mechanics
References
3- hackerone.com/reports/317125nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-488m-6gh8-9j36ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-3735ghsaADVISORY
News mentions
0No linked articles in our index yet.