Verdaccio · Verdaccio · CVE-2019-14772
**Name of the Vulnerable Software and Affected Versions**
verdaccio versions prior to 3.12.0
**Description**
The issue is a Cross-Site Scripting (XSS) vulnerability, where malicious packages with JavaScript content can be executed in the User Interface, potentially stealing user credentials.
**Recommendations**
For versions prior to 3.12.0, upgrade to version 3.12.0 or later, or migrate to a major version 4.0.0 or later to fix the issue.
At the moment, there is no workaround available without upgrading.