All the vulnerabilities related to the version 4.1.0 of the package
Cross-site Scripting in sanitize-url
The package @braintree/sanitize-url
before 6.0.0 is vulnerable to Cross-site Scripting (XSS) due to improper sanitization in the sanitizeUrl
function.
@braintree/sanitize-url Cross-site Scripting vulnerability
sanitize-url (aka @braintree/sanitize-url) before 6.0.1 allows XSS via HTML entities.