GHSA-rv8p-rr2h-fgpg
@apollo/experimental-nextjs-app-support Cross-site Scripting vulnerability
Quick fix
GHSA-rv8p-rr2h-fgpg — @apollo/experimental-nextjs-app-support: upgrade to the fixed version with the command below.
npm install @apollo/experimental-nextjs-app-support@0.7.0Details
### Impact
The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. This vulnerability arises from improper handling of untrusted input when @apollo/experimental-apollo-client-nextjs performs server-side rendering of HTML pages. To fix this vulnerability, we implemented appropriate escaping to prevent javascript injection into rendered pages.
### Patches
To fix this issue, please update to version 0.7.0 or later.
### Workarounds
There are no known workarounds for this issue. Please update to version 0.7.0
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.7.0npm install @apollo/experimental-nextjs-app-support@0.7.0References
- https://github.com/apollographql/apollo-client-nextjs/security/advisories/GHSA-rv8p-rr2h-fgpg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-23841[ADVISORY]
- https://github.com/apollographql/apollo-client-nextjs/commit/b92bc42abd5f8e17d4db361c36bd08e4f541a46b[WEB]
- https://github.com/apollographql/apollo-client-nextjs[PACKAGE]