Skip to content
plotly.jsGHSA-2fqv-h3r5-m4vf

Cross Site Scripting (XSS) in plotly.js

Medium6.1CVE-2017-1000006 · Published Oct 24, 2017 · updated Nov 8, 2023

Affected versions of `plotly.js` are vulnerable to cross-site scripting if an attacker can convince a user to visit a malicious plot on a site using this package. ## Recommendation Update to 1.16.0 or later.

GitHub advisory

Affected versions

PackageAffectedFixed in
plotly.js
npm
< 1.16.01.16.0
Details and references

More plotly.js advisories

All plotly.js
Advisory
plotly.js prototype pollution vulnerability
Critical9.8Jan 3, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.