tsup is vulnerable to Cross-Site Scripting
21
Low Risk
Affected versions of this package are vulnerable to DOM Clobbering due to insufficient validation of script tags in the URL resolution logic. The getImportMetaUrl function insecurely relies on document.currentScript and document.baseURI without proper sanitization, allowing attackers to inject malicious HTML elements that override these properties. An attacker could exploit this by clobbering document.currentScript.src or document.baseURI with controlled values, potentially redirecting script imports to arbitrary malicious URLs and enabling cross-site scripting (XSS) or code execution.
You are affected if you are using a version that falls within the vulnerable range.
tsup is vulnerable to Cross-Site Scripting in versions 5.0.0 - 8.5.0.
Upgrade the tsup library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant