axnsan12 / drf-yasg

Automated generation of real Swagger/OpenAPI 2.0 schemas from Django REST Framework code.
https://drf-yasg.readthedocs.io/en/stable/
Other
3.4k stars 437 forks source link

Vulnerability Issue #864

Open krishdeva01 opened 1 year ago

krishdeva01 commented 1 year ago

Bug Report

Description

Vulnerability Issue in swagger-dist-ui/swagger-bundle.js file High vulnerability: mXSS-based bypass caused by nested forms inside MATHML GHSA Screenshot 2023-08-11 at 8 46 28 AM

A clear and concise description of the problem... ## Is this a regression? Yes, the previous version in which this bug was not present was: ... ## Minimal Reproduction ```code ``` ## Stack trace / Error message ```code ```

Your Environment