Vulnerabilities/

Stage.js DOM Clobbering vulnerabilty

Severity:
Medium

Description

Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
stage-js
Anything's wrong? Let us know Last updated on June 30, 2025