Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2023-42503 Vulnerability in maven package org.apache.commons:commons-compress
CVE-2022-24785 Vulnerability in maven package org.fujion.webjars:moment
CVE-2022-31692 Vulnerability in maven package org.springframework.security:spring-security-web
CVE-2022-39225 Vulnerability in npm package parse-server
CVE-2021-23341 Vulnerability in maven package org.webjars:prismjs