Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2020-7660 Vulnerability in maven package org.webjars.npm:serialize-javascript
CVE-2018-19837 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2023-34238 Vulnerability in npm package gatsby-plugin-mdx
CVE-2023-50249 Vulnerability in npm package @sentry/astro
CVE-2021-39233 Vulnerability in maven package org.apache.ozone:ozone-main