You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We discovered a DOM Clobbering vulnerability in Vite when building scripts to cjs/iife/umd output format. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an img tag with an unsanitized name attribute) are present.
The text was updated successfully, but these errors were encountered:
Dependabot Alert: Vite's server.fs.deny is bypassed when using ?import&raw #651
Dependabot Alert: Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS #650
Dependabot Alert: Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS #650
Biobased in Training #663
Dependabot Alert: Vite's server.fs.deny is bypassed when using ?import&raw #651
Dependabot Alert: Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS #650
Dependabot Alert: Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS #650
Biobased in Training #663
We discovered a DOM Clobbering vulnerability in Vite when building scripts to cjs/iife/umd output format. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an img tag with an unsanitized name attribute) are present.
The text was updated successfully, but these errors were encountered: