Skip to content

sweetalert2 v11.6.14 and above contains potentially undesirable behavior

Low severity GitHub Reviewed Published Jul 10, 2023 to the GitHub Advisory Database • Updated Nov 7, 2023

Package

npm sweetalert2 (npm)

Affected versions

>= 11.6.14

Patched versions

None

Description

sweetalert2 versions 11.6.14 and above have potentially undesirable behavior. The package outputs audio and/or video messages that do not pertain to the functionality of the package when run on specific tlds. This functionality is documented on the project's readme

References

Published to the GitHub Advisory Database Jul 10, 2023
Reviewed Jul 10, 2023
Last updated Nov 7, 2023

Severity

Low

Weaknesses

CVE ID

No known CVE

GHSA ID

GHSA-mrr8-v49w-3333

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.