Description
What kind of vulnerability is it? Who is impacted?
Cross-Site Scripting XSS, malicious packages with content Javascript that might be executed in the User Interface stealing user credentials.
Recommendation
Update the verdaccio package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.12.0
- Patched version(s): 3.12.0
References
Related Issues
- Bootstrap Vulnerable to Cross-Site Scripting - CVE-2019-8331
- Layui cross-site scripting (XSS) vulnerability - CVE-2023-50550
- ghtml Cross-Site Scripting (XSS) vulnerability - CVE-2024-37166
- @tiptap/extension-link vulnerable to Cross-site Scripting (XSS) - CVE-2025-14284
- Tags:
- npm
- verdaccio
Anything's wrong? Let us know Last updated on January 09, 2023