Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2017-18239 Vulnerability in maven package com.jason-goodwin:authentikat-jwt
CVE-2022-21208 Vulnerability in npm package node-opcua
CVE-2022-0722 Vulnerability in npm package parse-url
CVE-2021-41182 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui
CVE-2014-0230 Vulnerability in maven package org.apache.tomcat:catalina