GHSA-vwjj-2852-3765
GitHub Security Advisory
Cross-Site Scripting in forms
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Affected versions of `forms` do not properly escape HTML in generated forms, which may result in cross-site scripting.
## Recommendation
Update to version 1.3.0 or later.
Affected Packages
npm
forms
Affected versions:
0
(fixed in 1.3.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 31, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.