Vulnerability library
Security checkSeptember 03, 2024

Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmwebpack

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

We discovered a DOM Clobbering vulnerability in Webpack’s AutoPublicPathRuntimeModule. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an img tag with an unsanitized name attribute) are present.

Recommendation

Update the webpack package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 5.0.0-alpha.0, < 5.94.0
  • Patched version(s): 5.94.0

References

Could your website be exposed too?

SmartScanner can check your website for Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated September 03, 2024