DOM Clobbering Vulnerability in tsup Product from Vendor
CVE-2024-53384

5.1MEDIUM

Key Information:

Vendor

Vendor

Status
Vendor
CVE Published:
3 March 2025

What is CVE-2024-53384?

A vulnerability in tsup v8.3.4 allows attackers to exploit DOM clobbering techniques. By manipulating the import.meta.url, an attacker can craft a malicious script that accesses the document.currentScript in cjs_shims.js components, leading to arbitrary code execution. This highlights the need for security measures to prevent unauthorized script execution within the application.

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.