smoothie@1.35.0 vulnerabilities

Smoothie Charts: smooooooth JavaScript charts for realtime streaming data

Direct Vulnerabilities

Known vulnerabilities in the smoothie package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

smoothie is a Smoothie Charts: smooooooth JavaScript charts for realtime streaming data

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

How to fix Cross-site Scripting (XSS)?

Upgrade smoothie to version 1.36.1 or higher.

>=1.31.0 <1.36.1