CVE-2024-53382

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-53382
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-53382.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-53382
Aliases
Downstream
Related
Published
2025-03-03T07:15:33Z
Modified
2025-10-10T04:58:46.059730Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

References

Affected packages

Git / github.com/prismjs/prism

Affected ranges

Type
GIT
Repo
https://github.com/prismjs/prism
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

1.*

1.4.0
1.5.0
1.5.1

v1.*

v1.0.0
v1.0.1
v1.1.0
v1.10.0
v1.11.0
v1.12.0
v1.12.1
v1.12.2
v1.13.0
v1.14.0
v1.15.0
v1.16.0
v1.17.0
v1.17.1
v1.18.0
v1.19.0
v1.2.0
v1.20.0
v1.21.0
v1.22.0
v1.23.0
v1.24.0
v1.24.1
v1.25.0
v1.26.0
v1.27.0
v1.28.0
v1.29.0
v1.3.0
v1.4.1
v1.6.0
v1.7.0
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.9.0