Medium severity6.1NVD Advisory· Published May 24, 2019· Updated Jun 17, 2026
CVE-2019-12313
CVE-2019-12313
Description
XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shavenpm | < 2.5.3 | 2.5.3 |
Affected products
3- Shave/Shavedescription
Patches
Vulnerability mechanics
References
5- github.com/dollarshaveclub/shave/commit/da7371b0531ba14eae48ef1bb1456a3de4cfa954nvdPatchThird Party AdvisoryWEB
- github.com/dollarshaveclub/shave/compare/852b537...da7371bnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-gh4g-3gm9-5wrqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-12313ghsaADVISORY
- www.npmjs.com/advisories/822nvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.