Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which which can lead to a cross-site scripting (XSS) vulnerability.
{
"constraint": ">= 8.0.0 < 10.5.9"
}{
"constraint": ">= 10.6.0 < 10.6.7"
}