Description
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
Remediation
References
https://github.com/webtorrent/webtorrent/compare/v0.107.5...v0.107.6
https://github.com/webtorrent/webtorrent/pull/1714
https://hackerone.com/reports/681617
Related Vulnerabilities
CVE-2020-5230 Vulnerability in maven package org.opencastproject:base
CVE-2016-10531 Vulnerability in maven package org.webjars.bower:marked
CVE-2023-35926 Vulnerability in npm package @backstage/plugin-scaffolder-backend
CVE-2020-28433 Vulnerability in npm package node-latex-pdf
CVE-2018-20000 Vulnerability in maven package org.bedework:bw-webdav