Headline
GHSA-cx3j-qqxj-9597: Critters Cross-site Scripting Vulnerability
Impact
Critters version 0.0.17-0.0.19 have an issue when parsing the HTML which leads to a potential cross-site scripting (XSS) bug.
Patches
The bug has been fixed in v0.0.20
.
Workarounds
Upgrading Critters version to >0.0.20
is the easiest fix. This is a non breaking version upgrade so we recommend all users to use v0.0.20
.
Critters Cross-site Scripting Vulnerability
High severity GitHub Reviewed Published Aug 9, 2023 in GoogleChromeLabs/critters • Updated Aug 11, 2023
Related news
CVE-2023-3481: Critical CSS inlining XSS Vulnerability Advisory
Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XSS) bug. We recommend upgrading to version 0.0.20 of the extension.