CVE-2024-53261: @sveltejs/kit vulnerable to XSS on dev mode 404 page
(updated )
“Unsanitized input from the request URL flows into end
, where it is used to render an HTML page returned to the user. This may result in a Cross-Site Scripting attack (XSS).”
References
- github.com/advisories/GHSA-rjjv-87mx-6x3h
- github.com/sveltejs/kit
- github.com/sveltejs/kit/commit/d338d4635a7fd947ba5112df6ee632c4a0979438
- github.com/sveltejs/kit/pull/13039
- github.com/sveltejs/kit/releases/tag/%40sveltejs%2Fkit%402.8.3
- github.com/sveltejs/kit/security/advisories/GHSA-rjjv-87mx-6x3h
- nvd.nist.gov/vuln/detail/CVE-2024-53261
Detect and mitigate CVE-2024-53261 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →