Skip to content

Conversation

@ljharb
Copy link

@ljharb ljharb commented Jan 16, 2026

Updates

  • Affected products

Comments

  • Earlier versions (0.3.0-0.3.2) don't have escapeHTML at all
  • There are no versions between 0.3.3 and 0.5.0

Copilot AI review requested due to automatic review settings January 16, 2026 21:41
@github-actions github-actions bot changed the base branch from main to ljharb/advisory-improvement-6661 January 16, 2026 21:41
@shelbyc
Copy link
Contributor

shelbyc commented Jan 16, 2026

Hi @ljharb, your findings are consistent with jashkenas/backbone@7ae0384, the commit that introduces escapeHTML, being tagged with 0.3.3.

@advisory-database advisory-database bot merged commit f26d986 into ljharb/advisory-improvement-6661 Jan 16, 2026
7 of 8 checks passed
@advisory-database
Copy link
Contributor

Hi @ljharb! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the ljharb-GHSA-j6p2-cx3w-6jcp branch January 16, 2026 22:08
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates a GitHub Security Advisory (GHSA) for a Cross-Site Scripting vulnerability in the backbone npm package. The update corrects the version range information for affected products, clarifying that the vulnerability specifically affects version 0.3.3, not all versions from 0 onwards.

Changes:

  • Modified the "introduced" version from "0" to "0.3.3" to reflect that earlier versions (0.3.0-0.3.2) did not have the vulnerable escapeHTML functionality
  • Added an explicit "versions" array listing the specific affected version (0.3.3)
  • Updated the "modified" timestamp to reflect the advisory change

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants