Skip to content

Resolved "DOM clobbering gadget in rollup bundled scripts leading to XSS"

Choose a tag to compare

@Stassi Stassi released this 05 Oct 06:33
· 446 commits to main since this release

Changelog: v0.0.29...v0.0.30
Pull request: #30
Resolves potential vulnerability: DOM clobbering gadget in rollup bundled scripts leading to XSS

Resolution to potential vulnerability

A high-severity DOM clobbering vulnerability was identified in Rollup-bundled scripts when using formats like cjs, umd, or iife. This allowed attackers to manipulate the document.currentScript property and dynamically load scripts from malicious sources, potentially leading to cross-site scripting (XSS).

View the full security disclosure at the project's security policy document.

Solution

Installed rollup@^4.22.4, resolving the potential vulnerability.

Update required

If any project requires a version of @stassi/leaflet prior to v0.0.30, run npm update immediately to ensure the latest security updates are received.