Skip to content

Security Issue with plotly.js #391

@jiyuan12354

Description

@jiyuan12354

Firstly, I would like to express my gratitude to the SurveyJS team for providing such a robust open-source tool. Our company was so impressed that we didn’t hesitate to purchase the pro plan.

However, we’ve encountered a problem that we need your assistance with. Our company has a portal site that relies on [email protected]. Our security team has discovered a security issue with this version.
Snipaste_2024-01-10_15-18-06

Snipaste_2024-01-10_15-10-42

Even after updating to the latest version of survey-analytics, which includes [email protected], the issue persists as this version of plotly.js does not contain the necessary fix.

Is there any possibility of updating to [email protected], which we believe has the required security fix? Alternatively, could you suggest any other methods to circumvent this security issue?

We look forward to your response and thank you in advance for your help.

I hope this helps! Let me know if you need further assistance.

refer to:
Fixed
Fix potential prototype pollution in plot API calls [#6703, 6704]

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions