Description
Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an application compares untrusted JSON/object data and renders annotated formatter output in the DOM, attacker-controlled HTML can be interpreted by the browser, resulting in XSS.
Problem types
Credits
Yuki Matsuhashi
References
security.snyk.io/vuln/SNYK-JS-JSONDIFFPATCH-16635946
gist.github.com/...tsuhashi/72ed072d919f3c52adba298faa6a7da5
github.com/...ommit/232338b34c4653148ca2f44e897a765b72c8c98f