tsup DOM Clobbering vulnerability
Low severity
GitHub Reviewed
Published
Mar 3, 2025
to the GitHub Advisory Database
•
Updated Mar 3, 2025
Description
Published by the National Vulnerability Database
Mar 3, 2025
Published to the GitHub Advisory Database
Mar 3, 2025
Reviewed
Mar 3, 2025
Last updated
Mar 3, 2025
A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components
References