Intel

AIKIDO-2024-10299

@lwc/shared is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 30, 2024

20

Low Risk

This Affects:

js@lwc/shared
2.5.0 - 8.1.1
Fixed in 8.1.2
Are you affected? Scan for Free

TL;DR

Affected versions of the package allow Cross-site Scripting (XSS). Setting innerHTML outside of lwc:inner-html is possible, which becomes a vulnerability if a proper sanitizing hook is not used.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@lwc/shared is vulnerable to Cross-site Scripting (XSS) in versions 2.5.0 - 8.1.1.

How to fix this

Upgrade the @lwc/shared library to the patch version.