Versions of the package spin.js before 3.0.0 are...
Low severity
Unreviewed
Published
Mar 11, 2026
to the GitHub Advisory Database
•
Updated Mar 11, 2026
Description
Published by the National Vulnerability Database
Mar 11, 2026
Published to the GitHub Advisory Database
Mar 11, 2026
Last updated
Mar 11, 2026
Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a crafted URL achieving a prototype pollution first, before being able to execute arbitrary JavaScript in the context of the user's browser.
References