PT-2024-32385 · Rollup+1 · Rollup+1

Ishmeals

+2

·

Published

2024-09-23

·

Updated

2025-11-01

·

CVE-2024-47068

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Rollup versions prior to 2.79.2, 3.29.5, and 4.22.4
Description The issue is related to a DOM Clobbering vulnerability in Rollup when bundling scripts with properties from import.meta (e.g., import.meta.url) in cjs/umd/iife format. This vulnerability can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an img tag with an unsanitized name attribute) are present. The DOM Clobbering gadget can be exploited by an attacker to load scripts from an attacker-controlled server.
Recommendations For versions prior to 2.79.2, update to version 2.79.2 or later. For versions prior to 3.29.5, update to version 3.29.5 or later. For versions prior to 4.22.4, update to version 4.22.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47068
GHSA-GCX4-MW62-G8WM
OPENSUSE-SU-2025:14663-1

Affected Products

Debian
Rollup