Description
The @tanstack/react-query-next-experimental NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this, an attacker would need to either inject malicious input or arrange to have malicious input be returned from an endpoint.
Recommendation
Update the @tanstack/react-query-next-experimental package to the latest compatible version. Followings are version details:
- Affected version(s): >= 5.0.0, < 5.18.0
- Patched version(s): 5.18.0
References
Related Issues
- Cross-site scripting vulnerability in TinyMCE - tinymce - CVE-2024-21911
- Cross-site scripting vulnerability in TinyMCE plugins - CVE-2024-21910
- TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option - CVE-2024-38356
- TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements - CVE-2024-38357
You might also like:
- Tags:
- npm
- @tanstack/react-query-next-experimental
Anything's wrong? Let us know Last updated on January 30, 2024


