CVE-2021-3377
05.03.2021, 21:15
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.
Vendor | Product | Version |
---|---|---|
ansi_up_project | ansi_up | 𝑥 < 5.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References