Vulnerabilities/

DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS

Severity:
High

Description

We discovered a DOM Clobbering vulnerability in rollup when bundling scripts that use import.meta.url or with plugins that emit and reference asset files from code in cjs/umd/iife format. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g.

Recommendation

Update the rollup package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
rollup
Anything's wrong? Let us know Last updated on September 26, 2024

This issue is available in SmartScanner Professional

See Pricing