PoC Index

CVE-2024-53384

MEDIUM 5.1EPSS 0.2%

A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components

CVSS v4.0
2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P
CVSS v3.1
5.1 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.24% chance of exploitation in the next 30 days, 16th percentile
Published
2025-03-03
Updated
2025-03-05

Proof-of-concept exploits (1)

References

Related