{"id":"GHSA-9r7h-6639-v5mw","summary":"Cross-Site Scripting in bootstrap-select","details":"Versions of `bootstrap-select` prior to 1.13.6 are vulnerable to Cross-Site Scripting (XSS).  The package does not escape `title` values on `\u003coption\u003e` tags. This may allow attackers to execute arbitrary JavaScript in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 1.13.6 or later.","aliases":["CVE-2019-20921","GHSA-7c82-mp33-r854","SNYK-JS-BOOTSTRAPSELECT-570457"],"modified":"2026-05-07T05:01:17.994234131Z","published":"2020-09-03T15:54:00Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-08-31T19:02:09Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/dimpu/ngx-md/issues/129"},{"type":"WEB","url":"https://github.com/snapappointments/bootstrap-select/issues/2199"},{"type":"PACKAGE","url":"https://github.com/snapappointments/bootstrap-select"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1522"}],"affected":[{"package":{"name":"bootstrap-select","ecosystem":"npm","purl":"pkg:npm/bootstrap-select"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-9r7h-6639-v5mw/GHSA-9r7h-6639-v5mw.json"}}],"schema_version":"1.9.0"}