First published: Tue Nov 14 2023(Updated: )
DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
Affected Software | Affected Version | How to fix |
---|---|---|
npm/dompurify | <1.0.11 | 1.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is GHSA-8hgg-xxm5-3873.
The title of this vulnerability is 'DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.'
The severity of this vulnerability is medium with a severity value of 6.1.
The CVE ID associated with this vulnerability is CVE-2019-25155.
To fix this vulnerability, update DOMPurify to version 1.0.11 or higher.