Loading HuntDB...

GHSA-26q7-g57v-mxcp

GitHub Security Advisory

HTML Injection in shout

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Affected versions of `shout` do not escape the `/topic` command in messages, and are therefore vulnerable to cross-site scripting.

## Recommendation

Update to version 0.50.0 or later.

Affected Packages

npm shout
Affected versions: 0.44.0 (fixed in 0.50.0)

Related CVEs

Key Information

GHSA ID
GHSA-26q7-g57v-mxcp
Published
November 7, 2018 12:28 AM
Last Modified
August 31, 2020 6:19 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
shout
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.