CVE-2024-53384: Egoist Tsup
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components
Affected products
- Egoist Tsup: version 8.3.4 only
Published 2025-03-03. Last modified 2026-06-17.