Users that use Cross-Origin communication and send sensitive information make it possible for this data to be intercepted. This is not a big impact because it happens only on the same browser.
It has been patched in version 1.10.0
The only workaround is to not send sensitive information with sysend messages.
{
"cwe_ids": [
"CWE-200",
"CWE-346"
],
"github_reviewed": true,
"github_reviewed_at": "2022-03-14T22:43:23Z",
"nvd_published_at": "2022-03-14T23:15:00Z",
"severity": "MODERATE"
}