@tawk.to/tawk-messenger-vue-3@1.0.3 vulnerabilities

Official Vue 3 plugin for Tawk messenger

Direct Vulnerabilities

Known vulnerabilities in the @tawk.to/tawk-messenger-vue-3 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

@tawk.to/tawk-messenger-vue-3 is an Official Vue 3 plugin for Tawk messenger

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the tawkFileUpload endpoint in the chatbot. An attacker can execute arbitrary JavaScript code in the browser of other users by uploading a crafted PDF containing a malicious payload, which is then rendered without proper sanitization. This can lead to theft of sensitive user data or unauthorized actions performed on behalf of affected users.

How to fix Cross-site Scripting (XSS)?

There is no fixed version for @tawk.to/tawk-messenger-vue-3.

>=0.0.0