@stripe/connect-js is vulnerable to HTML Clobbering
20
Low Risk
Affected versions of this package are vulnerable to HTML clobbering, where malicious HTML elements can interfere with the initialization of connect.js. If the host page's <head> contains nested <a> tags with id= StripeConnect and name= init, it may falsely assume connect.js is initialized. An attacker can inject HTML like <a id='StripeConnect'><a id='StripeConnect' name='init' href='stripe'></a></a>, leading to improper script execution, security bypasses, or other unintended behaviors.
You are affected if you are using a version that falls within the vulnerable range.
@stripe/connect-js is vulnerable to HTML Clobbering in versions 3.0.0 - 3.3.22.
Upgrade the @stripe/connect-js library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant