VYPR

npm package

highlight.js

pkg:npm/highlight.js

Vulnerabilities (1)

  • CVE-2020-26237MedNov 24, 2020
    affected < 9.18.2fixed 9.18.2

    Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting.