CVE-2024-53382
published 2025-03-03CVE-2024-53382: Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript)…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.30%
22.0th percentile
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-prismjs | < node-prismjs 1.30.0+dfsg+~1.26.5-1 (forky) | node-prismjs 1.30.0+dfsg+~1.26.5-1 (forky) |
| prismjs | prism | <= 1.29.0 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin
vendor_redhat·2025-03-03·CVSS 4.9
CVE-2024-53382 [MEDIUM] CWE-94 prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin
prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
A flaw was found in the prism-autoloader plugin of the Prism library. The prism-autoloader plugin uses `document.currentScript` as the base URL for dynamically loading other dependencies and, in certain circumstances, can be vulnerable to a DOM Clobbering attack. This issue could lead to Cross-site scripting (XSS) attacks on web pages that embed Prism and allow users to inject scriptless HTML elements, such as an `img` tag with a controlled `name` attribut
Debian
CVE-2024-53382: node-prismjs - Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for...
vendor_debian·2024·CVSS 4.9
CVE-2024-53382 [MEDIUM] CVE-2024-53382: node-prismjs - Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for...
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.30.0+dfsg+~1.26.5-1)
sid: resolved (fixed in 1.30.0+dfsg+~1.26.5-1)
trixie: open
OSV
CVE-2024-53382: Prism (aka PrismJS) through 1
osv·2025-03-03·CVSS 5.4
CVE-2024-53382 [MEDIUM] CVE-2024-53382: Prism (aka PrismJS) through 1
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
GHSA
PrismJS DOM Clobbering vulnerability
ghsa·2025-03-03
CVE-2024-53382 [MEDIUM] CWE-79 PrismJS DOM Clobbering vulnerability
PrismJS DOM Clobbering vulnerability
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
OSV
PrismJS DOM Clobbering vulnerability
osv·2025-03-03
CVE-2024-53382 [MEDIUM] PrismJS DOM Clobbering vulnerability
PrismJS DOM Clobbering vulnerability
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
No detection rules found.
No public exploits indexed.
2025-03-03
Published