CVE-2017-0928: Theguardian Html-Janitor

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.

Affected products

Published 2018-06-04. Last modified 2026-06-17.