Skip to content

Autogen Studio - PrismJS DOM Clobbering vulnerability #5823

Closed
@rysweet

Description

@rysweet

What happened?

Describe the bug
Dependabot vulnerability: https://github.com/microsoft/autogen/security/dependabot/36

Package
Affected versions
Patched version
prismjs
(npm)
<= 1.29.0
None
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

Which packages was the bug in?

AutoGen Studio (autogensudio)

AutoGen library version.

Python dev (main branch)

Other library version.

No response

Model used

No response

Model provider

None

Other model provider

No response

Python version

None

.NET version

None

Operating system

None

Metadata

Metadata

Assignees

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions