The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| express-xss-sanitizer(npm) | 0 | 1.1.3 | N/A |
CVSS Metrics