MEDIUM4.2
GHSA-g3ch-rx76-35fx
vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
Details
A vulnerability has been discovered in vue-template-compiler, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code. Vue 2 has reached End-of-Life. This vulnerability has been patched in Vue 3.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/vue-template-compiler
Introduced in:
2.0.0No fixed version published yet for vue-template-compiler (npm). Pin to a known-safe version or switch to an alternative.