VYPR
Medium severity5.4NVD Advisory· Published Mar 16, 2022· Updated Jun 17, 2026

CVE-2021-23648

CVE-2021-23648

Description

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@braintree/sanitize-urlnpm
< 6.0.06.0.0

Affected products

7

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.