Ansi Up is a utility library for converting ANSI escape sequences to HTML markup, a function relied upon by terminal-emulation and log-display components across web and desktop applications. The primary identified weakness class involves improper neutralization of user-controlled input during HTML generation, a characteristic risk for libraries that bridge terminal output to web display contexts. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ansi Up Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3377MEDIUM The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this fea | Mar 5, 2021 | 6.1 | 34 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ansi Up Project.
Media articles that mention a CVE ID that affects a product developed by Ansi Up Project — matched by CVE ID, not by vendor name.