All the vulnerabilities related to the version 0.1.2 of the package
Cross-Site Scripting in backbone
Affected versions of backbone
are vulnerable to cross-site scripting when users are allowed to supply input to the Model#Escape
function, and the output is then written to the DOM.
The vulnerability occurs as a result of the regular expression used to encode metacharacters failing to take HTML Entities such as <
into account.
Update to version 0.5.0 or later.