Description
This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).
Remediation
References
https://github.com/rooseveltframework/teddy/pull/518
https://github.com/rooseveltframework/teddy/releases/tag/0.5.9
https://snyk.io/vuln/SNYK-JS-TEDDY-1579557
Related Vulnerabilities
CVE-2021-41183 Vulnerability in maven package org.webjars:jquery-ui
CVE-2023-24057 Vulnerability in maven package org.hl7.fhir.publisher:org.hl7.fhir.publisher.core
CVE-2020-7760 Vulnerability in maven package org.webjars.npm:codemirror
CVE-2023-26149 Vulnerability in maven package org.webjars.npm:quill-mention
CVE-2022-31170 Vulnerability in npm package @openzeppelin/contracts-upgradeable