XSS vulnerability on Swagger UI
Open
- Dominant language
- Python
- Stars
- 3.7k
- Forks
- 525
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/seanmarpo/webjars-swagger-xss
Should we be worried about this, it seems to be fixed a version of swagger-ui higher than 3.36.2? Thanks.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the linked webjars-swagger-xss report and identify where this project selects or bundles its Swagger UI version; the issue names no file or test. Done means confirming whether the affected version is used and documenting a concrete upgrade or mitigation path for the project.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- api, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100