Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Jun 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Prismjs
Prismjs prism |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:prismjs:prism:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Prismjs
Prismjs prism |
Wed, 12 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 03 Mar 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements. | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-03T00:00:00.000Z
Updated: 2025-03-03T21:53:33.210Z
Reserved: 2024-11-20T00:00:00.000Z
Link: CVE-2024-53382

Updated: 2025-03-03T21:53:13.145Z

Status : Analyzed
Published: 2025-03-03T07:15:33.397
Modified: 2025-06-27T13:08:24.660
Link: CVE-2024-53382
