VYPR
Medium severity5.7NVD Advisory· Published Aug 21, 2023· Updated Jun 17, 2026

CVE-2023-3481

CVE-2023-3481

Description

Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XSS) bug. We recommend upgrading to version 0.0.20 of the extension.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
crittersnpm
>= 0.0.17, < 0.0.200.0.20

Affected products

3
  • Google/Critters2 versions
    cpe:2.3:a:google:critters:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:google:critters:*:*:*:*:*:*:*:*range: >=0.0.17,<=0.0.19
    • (no CPE)range: 0.0.17
  • ghsa-coords
    Range: >= 0.0.17, < 0.0.20

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.