Excalidraw Vulnerable to Cross-site Scripting (XSS) via Embedded Links in Whiteboard Objects
CVE-2023-26140
6.1MEDIUM
What is CVE-2023-26140?
Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.
Affected Version(s)
@excalidraw/excalidraw 0.0.0
