CVE-2024-53384
MEDIUM 5.1EPSS 0.2%
A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components
- CVSS v4.0
- 2.1 LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P - CVSS v3.1
- 5.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS
- 0.24% chance of exploitation in the next 30 days, 16th percentile
- Published
- 2025-03-03
- Updated
- 2025-03-05