Medium severity5.4NVD Advisory· Published Mar 16, 2022· Updated Jun 17, 2026
CVE-2021-23648
CVE-2021-23648
Description
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@braintree/sanitize-urlnpm | < 6.0.0 | 6.0.0 |
Affected products
7- cpe:2.3:a:paypal:braintree\/sanitize-url:*:*:*:*:*:node.js:*:*Range: <6.0.0
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- @braintree/sanitize-urldescription
- ghsa-coords2 versions
< 6.0.0+ 1 more
- (no CPE)range: < 6.0.0
- (no CPE)range: < 7.5.15-3.el8
Patches
Vulnerability mechanics
References
12- github.com/braintree/sanitize-url/pull/40nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/braintree/sanitize-url/pull/40/commits/e5afda45d9833682b705f73fc2c1265d34832183nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-hqq7-2q2v-82xqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23648ghsaADVISORY
- github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11nvdBroken LinkWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3DghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRHghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/nvd
News mentions
0No linked articles in our index yet.