Resolved "DOM clobbering gadget in rollup bundled scripts leading to XSS"
Changelog: v0.0.29...v0.0.30
Pull request: #30
Resolves potential vulnerability: DOM clobbering gadget in rollup bundled scripts leading to XSS
Resolution to potential vulnerability
A high-severity DOM clobbering vulnerability was identified in Rollup-bundled scripts when using formats like cjs, umd, or iife. This allowed attackers to manipulate the document.currentScript property and dynamically load scripts from malicious sources, potentially leading to cross-site scripting (XSS).
View the full security disclosure at the project's security policy document.
Solution
Installed rollup@^4.22.4, resolving the potential vulnerability.
Update required
If any project requires a version of @stassi/leaflet prior to v0.0.30, run npm update immediately to ensure the latest security updates are received.