@stripe/connect-js is vulnerable to HTML Clobbering
20
Low Risk
Affected versions of this package are vulnerable to HTML clobbering, where malicious HTML elements can interfere with the initialization of connect.js. If the host page's <head> contains nested <a> tags with id= StripeConnect and name= init, it may falsely assume connect.js is initialized. An attacker can inject HTML like <a id='StripeConnect'><a id='StripeConnect' name='init' href='stripe'></a></a>, leading to improper script execution, security bypasses, or other unintended behaviors.
You are affected if you are using a version that falls within the vulnerable range.
@stripe/connect-js is vulnerable to HTML Clobbering in versions 3.0.0 - 3.3.22.
Upgrade the @stripe/connect-js library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant