{"id":"GHSA-hqq7-2q2v-82xq","summary":"Cross-site Scripting in sanitize-url","details":"The package `@braintree/sanitize-url` before 6.0.0 is vulnerable to Cross-site Scripting (XSS) due to improper sanitization in the `sanitizeUrl` function.","aliases":["CVE-2021-23648","SNYK-JS-BRAINTREESANITIZEURL-2339882"],"modified":"2026-05-07T04:56:48.794878171Z","published":"2022-03-17T00:00:24Z","database_specific":{"github_reviewed_at":"2022-03-19T00:01:56Z","nvd_published_at":"2022-03-16T16:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23648"},{"type":"WEB","url":"https://github.com/braintree/sanitize-url/pull/40"},{"type":"WEB","url":"https://github.com/braintree/sanitize-url/pull/40/commits/e5afda45d9833682b705f73fc2c1265d34832183"},{"type":"PACKAGE","url":"https://github.com/braintree/sanitize-url"},{"type":"WEB","url":"https://github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882"}],"affected":[{"package":{"name":"@braintree/sanitize-url","ecosystem":"npm","purl":"pkg:npm/%40braintree/sanitize-url"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-hqq7-2q2v-82xq/GHSA-hqq7-2q2v-82xq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}