CVE-2017-0928: Theguardian Html-Janitor
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.
Affected products
- Theguardian Html-Janitor: version 2.0.2 only
Published 2018-06-04. Last modified 2026-06-17.