CVE-2013-7451 (node.js)

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.