@nuxt/rspack-builder@3.12.2 vulnerabilities

rspack bundler for Nuxt

  • latest version

    3.15.4

  • latest non vulnerable version

  • first published

    4 months ago

  • latest version published

    1 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @nuxt/rspack-builder package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Exposed Dangerous Method or Function

    @nuxt/rspack-builder is a rspack bundler for Nuxt

    Affected versions of this package are vulnerable to Exposed Dangerous Method or Function when using webpack or rspack builder and navigating to a malicious website. An attacker can inject a script tag to request a classic script, which is not restricted by the same-origin policy. This allows the script to execute and access the window.webpackChunknuxt_app object. By utilizing Function::toString on the values within this object, the attacker can extract and display the source code.

    How to fix Exposed Dangerous Method or Function?

    Upgrade @nuxt/rspack-builder to version 3.15.3, 3.15.3 or higher.

    <3.15.3>=3.12.2 <3.15.3