express-xss-sanitizer

express-xss-sanitizer

Releases18
Frequency3 months 3 weeks
Last Release
Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack.

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM

The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth in sanitize in lib/sanitize.js for a JSON request body.