TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tanstack/react-query-next-experimental` NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this, an attacker would need to either inject malicious input or arrange to have malicious input be returned from an endpoint. To fix this issue, please update to version 5.18.0 or later.
References
Configurations
History
No history.
Information
Published : 2024-01-30 20:15
Updated : 2024-04-23 19:52
NVD link : CVE-2024-24558
Mitre link : CVE-2024-24558
CVE.ORG link : CVE-2024-24558
JSON object : View
Products Affected
tanstack
- react-query-next-experimental
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')