plotly.jsGHSA-2fqv-h3r5-m4vf
Cross Site Scripting (XSS) in plotly.js
Medium6.1CVE-2017-1000006 · Published Oct 24, 2017 · updated Nov 8, 2023
Affected versions of `plotly.js` are vulnerable to cross-site scripting if an attacker can convince a user to visit a malicious plot on a site using this package. ## Recommendation Update to 1.16.0 or later.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| plotly.js npm | < 1.16.0 | 1.16.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2017-1000006
More plotly.js advisories
All plotly.js| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 32024 | plotly.js prototype pollution vulnerability | Critical9.8 | 2.25.2 |