SCA: security update for express-xss-sanitizer (GHSA-3843-rr4g-m8jq)

high Tenable Self-Hosted Container Security Plugin ID 439346

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body,
req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack. A vulnerability has
been identified in versions prior to 2.0.2 where restrictive sanitization configurations are silently
ignored. In version 2.0.2, the validation logic has been updated to respect explicitly provided empty
configurations. Now, if allowedTags or allowedAttributes are provided (even if empty), they are passed
directly to sanitize-html without being overridden. (CVE-2026-33979)

Solution

Update the express-xss-sanitizer library and its related packages to version 2.0.2 or later.

See Also

https://github.com/advisories/GHSA-3843-rr4g-m8jq

Plugin Details

Severity: High

ID: 439346

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 3/27/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 52.04

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:C/A:N

CVSS Score Source: CVE-2026-33979

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/27/2026

Vulnerability Publication Date: 3/27/2026

Reference Information

CVE: CVE-2026-33979