Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. mapbox.js
  4. ›
  5. GMS-2016-6

GMS-2016-6: Content Injection via TileJSON Name

January 12, 2016

Mapbox.js is vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios.

References

  • hackerone.com/reports/99245

Code Behaviors & Features

Detect and mitigate GMS-2016-6 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.6.6, all versions starting from 2.0.0-beta0 before 2.2.4

Fixed versions

  • 1.6.6
  • 2.2.4

Solution

Upgrade to Mapbox.js version 2.2.4. If you are still using a 1.x version and unable to upgrade to 2.2.4, upgrade to 1.6.6. If you are unable to upgrade to either 2.2.4 or 1.6.6, you can also remove instances of L.mapbox.shareControl from your maps.

Source file

npm/mapbox.js/GMS-2016-6.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:34 +0000.