Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2018-25031 Vulnerability in maven package org.webjars.bower:swagger-ui
CVE-2020-26302 Vulnerability in maven package org.webjars.bowergithub.arasatasaygin:is.js
CVE-2019-10788 Vulnerability in npm package im-metadata
CVE-2020-24660 Vulnerability in npm package node-lemonldap-ng-handler
CVE-2011-2487 Vulnerability in maven package org.apache.ws.security:wss4j