Loading npm security reports…
Juniper omnibar web components
Public web-component properties and attributes are rendered with innerHTML without escaping. A host application that supplies attacker-controlled config could enable DOM XSS or unsafe navigation.
Unescaped public config strings flow into innerHTML templates in dist/product-switcher.js and dist/profile-switcher.js.
dist/product-switcher.jsView on unpkgUnescaped public config strings flow into innerHTML templates in dist/product-switcher.js and dist/profile-switcher.js.
dist/product-switcher.jsView on unpkg