Description
What kind of vulnerability is it? Who is impacted?
Cross-Site Scripting XSS, malicious packages with content Javascript that might be executed in the User Interface stealing user credentials.
Recommendation
Update the verdaccio package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.12.0
- Patched version(s): 3.12.0
References
Related Issues
- AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes - CVE-2019-14863
- Cross-Site Scripting in min-http-server - CVE-2019-5457
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- DOM-based cross-site scripting in Froala Editor - CVE-2019-19935
- Tags:
- npm
- verdaccio
Anything's wrong? Let us know Last updated on January 09, 2023