Skip to content

[Bug]: ⚠️ High Severity Vulnerability in Rollup Dependency (<2.79.2) #6857

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
2 of 10 tasks
wapatp opened this issue May 10, 2025 · 1 comment
Open
2 of 10 tasks
Labels
waiting for author Further information is requested from the author

Comments

@wapatp
Copy link

wapatp commented May 10, 2025

Describe the bug / 问题描述

Hi team,

While running npm audit, I encountered a high severity vulnerability in the rollup package bundled within your dependency chain.

Vulnerability: DOM Clobbering Gadget in rollup bundled scripts that leads to XSS
Severity: High
Affected Package: rollup (<2.79.2)
Fix: Upgrade to >=2.79.2
Advisory: GHSA-gcx4-mw62-g8wm

Image

Reproduction link / 复现链接

No response

Steps to Reproduce the Bug or Issue / 重现步骤

No response

Version / 版本

🆕 5.x

OS / 操作系统

  • macOS
  • Windows
  • Linux
  • Others / 其他

Browser / 浏览器

  • Chrome
  • Edge
  • Firefox
  • Safari (Limited support / 有限支持)
  • IE (Nonsupport / 不支持)
  • Others / 其他
@wapatp wapatp added the waiting for maintainer Triage or intervention needed from a maintainer label May 10, 2025
@hustcc
Copy link
Member

hustcc commented May 10, 2025

@wapatp Can help with a pr? 有兴趣来一个 pr 帮忙解决吗?

@hustcc hustcc added waiting for author Further information is requested from the author and removed waiting for maintainer Triage or intervention needed from a maintainer labels May 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
waiting for author Further information is requested from the author
Projects
None yet
Development

No branches or pull requests

2 participants