GHSA-g3ch-rx76-35fx
Dashboard / Vulnerabilities / GHSA-g3ch-rx76-35fx
Summary: vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
Details: A vulnerability has been discovered in vue-template-compiler, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code. Vue 2 has reached End-of-Life. This vulnerability has been patched in Vue 3.
References: https://nvd.nist.gov/vuln/detail/CVE-2024-6783, https://github.com/vuejs/vue, https://www.herodevs.com/vulnerability-directory/cve-2024-6783
Affected packages
Package
Name: vue-template-compiler
Purl: pkg:npm/vue-template-compiler
Affected ranges
Type: SEMVER
Events:
