Medium severity6.1NVD Advisory· Published Jul 30, 2018· Updated Jun 17, 2026
CVE-2018-3773
CVE-2018-3773
Description
There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the metascrape npm module <= 3.9.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
metascrapernpm | < 5.2.0 | 5.2.0 |
Affected products
3- cpe:2.3:a:metascraper_project:metascraper:*:*:*:*:*:node.js:*:*Range: <=3.9.2
- https://github.com/microlinkhq/metascraperv5Range: Not fixed
Patches
Vulnerability mechanics
References
5- hackerone.com/reports/309367nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-8f64-q7jc-ccgpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-3773ghsaADVISORY
- github.com/microlinkhq/metascraper/pull/169ghsaWEB
- www.npmjs.com/advisories/603ghsaWEB
News mentions
0No linked articles in our index yet.