VYPR

npm package

osm-static-maps

pkg:npm/osm-static-maps

Vulnerabilities (1)

  • CVE-2020-7749Oct 20, 2020
    affected < 3.9.0fixed 3.9.0

    This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an