XSS in @apollo/experimental-nextjs-app-support
CVE-2024-23841
8.2HIGH
What is CVE-2024-23841?
The Apollo Client support for Next.js, specifically the @apollo/experimental-apollo-client-nextjs NPM package, is susceptible to a cross-site scripting vulnerability. This issue can allow an attacker to inject malicious scripts through user input, which may be triggered by specific links or manipulated GraphQL server responses. To mitigate this vulnerability, users are advised to upgrade to version 0.7.0 or higher.
Affected Version(s)
apollo-client-nextjs < 0.7.0
