@polkadot/apps-config is vulnerable to Cross-site Scripting (XSS)
10
Low Risk
Affected versions of this package are vulnerable to clickjacking and UI redress attacks due to missing security headers (X-Frame-Options and Content-Security-Policy) in the app configuration, which fail to disallow frame embedding. An attacker could exploit this by embedding the application within a malicious webpage using an iframe, tricking users into interacting with hidden or disguised elements, potentially leading to unauthorized actions or data theft.
You are affected if you are using a version that falls within the vulnerable range.
@polkadot/apps-config is vulnerable to Cross-site Scripting (XSS) in versions 0.42.1 - 0.159.0.
Upgrade the @polkadot/apps-config library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant