CVE-2024-53384: Egoist Tsup

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components

Affected products

  • Egoist Tsup: version 8.3.4 only

Published 2025-03-03. Last modified 2026-06-17.