Description
What kind of vulnerability is it? Who is impacted?
Cross-Site Scripting XSS, malicious packages with content Javascript that might be executed in the User Interface stealing user credentials.
Recommendation
Update the verdaccio
package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.12.0
- Patched version(s): 3.12.0
References
Related Issues
- tarteaucitron Cross-site Scripting (XSS) - CVE-2025-1467
- Cross site scripting in markdown-to-jsx - CVE-2024-21535
- uPlot Prototype Pollution vulnerability - CVE-2024-21489
- FUXA local file inclusion vulnerability - CVE-2023-31718
- Tags:
- npm
- verdaccio
Anything's wrong? Let us know Last updated on January 09, 2023