Vulnerabilities/

@apollo/experimental-nextjs-app-support Cross-site Scripting vulnerability

Severity:
High

Description

The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. This vulnerability arises from improper handling of untrusted input when @apollo/experimental-apollo-client-nextjs performs server-side rendering of HTML pages.

Recommendation

Update the @apollo/experimental-nextjs-app-support package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@apollo/experimental-nextjs-app-support
Anything's wrong? Let us know Last updated on January 30, 2024