sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
{ "binaries": [ { "binary_name": "node-mermaid", "binary_version": "8.13.8+~cs10.4.16-1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-48345.json"