High severity7.3NVD Advisory· Published Sep 26, 2022· Updated Jun 17, 2026
CVE-2022-21169
CVE-2022-21169
Description
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
express-xss-sanitizernpm | < 1.1.3 | 1.1.3 |
Affected products
3- cpe:2.3:a:express_xss_sanitizer_project:express_xss_sanitizer:*:*:*:*:*:node.js:*:*Range: <1.1.3
- express-xss-sanitizer/express-xss-sanitizerdescription
Patches
Vulnerability mechanics
References
6- github.com/AhmedAdelFahim/express-xss-sanitizer/commit/3bf8aaaf4dbb1c209dcb8d87a82711a54c1ab39anvdPatchThird Party AdvisoryWEB
- runkit.com/embed/w306l6zfm7tunvdPatchThird Party AdvisoryURL RepurposedWEB
- github.com/AhmedAdelFahim/express-xss-sanitizer/issues/4nvdExploitIssue TrackingThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-EXPRESSXSSSANITIZER-3027443nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-grjp-4jmr-mjcwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-21169ghsaADVISORY
News mentions
0No linked articles in our index yet.