CVE-2021-23411

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction.

Date published : 2021-07-21

https://github.com/alexcorvi/anchorme.js/blob/gh-pages/src/transform.ts%23L81

https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1320695