Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2020-11994 Vulnerability in maven package org.apache.camel:camel-robotframework
CVE-2022-1929 Vulnerability in npm package devcert
CVE-2023-45277 Vulnerability in maven package org.yamcs:yamcs-core
CVE-2020-28276 Vulnerability in npm package deep-set
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js