html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.
The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.
Link | Tags |
---|---|
https://hackerone.com/reports/308158 | third party advisory |
https://github.com/guardian/html-janitor/issues/35 | third party advisory |