Medium severity6.1NVD Advisory· Published Feb 5, 2022· Updated Jun 17, 2026
CVE-2022-0437
CVE-2022-0437
Description
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
karmanpm | < 6.3.14 | 6.3.14 |
Affected products
3- karma-runner/karma-runner/karmav5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/karma-runner/karma/commit/839578c45a8ac42fbc1d72105f97eab77dd3eb8anvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/64b67ea1-5487-4382-a5f6-e8a95f798885nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-7x7c-qm48-pq9cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-0437ghsaADVISORY
- github.com/karma-runner/karma/releases/tag/v6.3.14ghsaWEB
News mentions
0No linked articles in our index yet.