PT-2021-20317 · Npm · Ansi Up
Published
2021-03-05
·
Updated
2025-11-03
·
CVE-2021-3377
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
ansi up versions prior to 5.0.0
Description:
The npm package ansi up is affected by a cross-site scripting (XSS) vulnerability due to insufficient URL sanitization when converting ANSI escape codes into HTML. This issue allows ANSI escape codes to create HTML hyperlinks.
Recommendations:
For versions prior to 5.0.0, update to version 5.0.0 to resolve the issue. As a temporary workaround, consider disabling the feature that allows ANSI escape codes to create HTML hyperlinks until the update is applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansi Up