Description
A vulnerability has been discovered in vue-template-compiler, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as Object.prototype.staticClass or Object.prototype.staticStyle to execute arbitrary JavaScript code. Vue 2 has reached End-of-Life.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 2.0.0, < 3.0.0
References
Could your website be exposed too?
SmartScanner can check your website for vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @mattkrick/sanitize-svg vulnerable to Cross-Site Scripting (XSS) - CVE-2023-22461
- jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin - CVE-2025-9910
- Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) - CVE-2018-9861
- Dash apps vulnerable to Cross-site Scripting - CVE-2024-21485


