CVE-2023-26140

Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.
Configurations

Configuration 1 (hide)

cpe:2.3:a:excalidraw:excalidraw:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2023-08-16 05:15

Updated : 2023-11-07 04:09


NVD link : CVE-2023-26140

Mitre link : CVE-2023-26140

CVE.ORG link : CVE-2023-26140


JSON object : View

Products Affected

excalidraw

  • excalidraw
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')