CVE-2024-53386

MEDIUM

stage.js < 0.8.10 - DOM Clobbering and Cross-Site Scripting via document.currentScript Shadowing

Title source: llm
STIX 2.1

Description

Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

Scores

CVSS v3 4.9
EPSS 0.0023
EPSS Percentile 13.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (2)
npm/stage-js 0npm
piqnt/stage.js < 0.8.10
Published Mar 03, 2025
Tracked Since Feb 18, 2026