Skip to content
2 changes: 1 addition & 1 deletion plugins/gcalendar/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@
"@tanstack/react-query": "^4.1.3",
"classnames": "^2.3.1",
"cross-fetch": "^3.1.5",
"dompurify": "^2.3.6",
"dompurify": "^2.5.4",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security: Outdated DOMPurify dependency (v2.3.6) with known XSS vulnerability (CVE-2024-45801) that could allow attackers to bypass sanitization through special nesting techniques and prototype pollution

"lodash": "^4.17.21",
"luxon": "^3.0.0",
"material-ui-popup-state": "^1.9.3",
Expand Down
Loading