CVE-2024-53382

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Mar 3, 2025
CWE ID 94

Summary

CVE-2024-53382 is a vulnerability affecting Prism (PrismJS) up to version 1.29.0. This issue allows an attacker to conduct DOM Clobbering, leading to Cross-Site Scripting (XSS) attacks. The flaw lies in the document.currentScript lookup mechanism, which can be manipulated by maliciously injected HTML elements, bypassing the expected JavaScript code execution. This vulnerability poses a significant risk, particularly for applications or websites that rely on user-generated content or third-party libraries like PrismJS.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share