4.1.3
4 years ago
12 days ago
Known vulnerabilities in the @nuxt/webpack-builder package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@nuxt/webpack-builder is a Webpack bundler for Nuxt Affected versions of this package are vulnerable to Exposed Dangerous Method or Function when using webpack or rspack builder and navigating to a malicious website.
An attacker can inject a script tag to request a classic script, which is not restricted by the same-origin policy. This allows the script to execute and access the How to fix Exposed Dangerous Method or Function? Upgrade | >=3.0.0 <3.15.3>=3.12.2 <3.15.3 |