CVE-2024-53384
CVSS 3.1 Score 5.1 of 10 (medium)
Details
Published Mar 3, 2025
Updated: Mar 5, 2025
CWE ID 79
Summary
CVE-2024-53384 is a DOM Clobbering vulnerability affecting tsup version 8.3.4. Maliciously crafted scripts can exploit this issue by manipulating the import.meta.url property and clobbering the document.currentScript object in the cjs_shims.js components. This vulnerability enables attackers to execute arbitrary code and potentially gain unauthorized access or control over affected systems. Developers using tsup version 8.3.4 are advised to update to a patched version or implement additional security measures to mitigate the risk of exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.