VYPR

Braintree\/sanitize URL

by Paypal

Source repositories

CVEs (2)

  • CVE-2022-48345MedFeb 24, 2023
    risk 0.33cvss 6.1epss 0.01

    sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.

  • CVE-2021-23648MedMar 16, 2022
    risk 0.00cvss 5.4epss 0.01

    The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.