Description
An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.5
References
Related Issues
- Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning - CVE-2026-46342
- Strapi does not verify the access or ID tokens issued during the OAuth flow - CVE-2023-22893
- Utils.readChallengeTx does not verify the server account signature - CVE-2021-32738
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - CVE-2025-53892
You might also like:
- Tags:
- npm
- xdlocalstorage
Anything's wrong? Let us know Last updated on July 17, 2023


