QID 981686
QID 981686: Nodejs (npm) Security Update for @nuxt/devalue (GHSA-6677-83pp-f862)
Versions of `@nuxt/devalue` prior to 1.2.3 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization attacker may inject arbitrary JavaScript code through object keys.
## Recommendation
Upgrade to version 1.2.3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6677-83pp-f862 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6677-83pp-f862 -
github.com/advisories/GHSA-6677-83pp-f862
CVEs related to QID 981686
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6677-83pp-f862 | @nuxt/devalue |
|