CVE-2021-26540
Improper Input Validation in sanitize-html
5.3
MEDIUM
CVSS 3.1
EPSS 0.29%
Description
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".
How to fix CVE-2021-26540
To remediate CVE-2021-26540, upgrade the affected package to a fixed version below.
- —upgrade to 2.3.2 or later
Is CVE-2021-26540 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.3.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |