Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2021-23449 Vulnerability in npm package vm2
CVE-2018-1002204 Vulnerability in maven package org.webjars:adm-zip
CVE-2019-13990 Vulnerability in maven package org.quartz-scheduler:quartz
CVE-2022-21700 Vulnerability in maven package io.micronaut:micronaut-http
CVE-2022-24433 Vulnerability in maven package org.webjars.npm:simple-git