Medium severity6.1NVD Advisory· Published Aug 29, 2019· Updated Jun 17, 2026
CVE-2019-15782
CVE-2019-15782
Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
webtorrentnpm | < 0.107.6 | 0.107.6 |
Affected products
3- WebTorrent/WebTorrentdescription
Patches
Vulnerability mechanics
References
8- github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6nvdPatchThird Party AdvisoryWEB
- github.com/webtorrent/webtorrent/pull/1714nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-gjh4-fcv3-whpqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-15782ghsaADVISORY
- github.com/webtorrent/webtorrent/commit/7e829b5d52c32d2e6d8f5fbcf0f8f418fffde083ghsaWEB
- hackerone.com/reports/681617nvdWEB
- snyk.io/vuln/SNYK-JS-WEBTORRENT-460351ghsaWEB
- www.npmjs.com/advisories/1158ghsaWEB
News mentions
0No linked articles in our index yet.