Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0403 | urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable to XSS. To exploit this an attacker would need to ensure that the response returns `html` tags and that the web-application is using streamed responses (non-RSC). This vulnerability is due to improper escaping of html-like characters in the response-stream. To fix this vulnerability upgrade to version 1.1.1 |
Github GHSA |
GHSA-qhjf-hm5j-335w | @urql/next Cross-site Scripting vulnerability |
Thu, 29 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-29T15:04:39.987Z
Reserved: 2024-01-25T15:09:40.208Z
Link: CVE-2024-24556
Updated: 2024-08-01T23:19:52.861Z
Status : Modified
Published: 2024-01-30T18:15:48.507
Modified: 2024-11-21T08:59:24.480
Link: CVE-2024-24556
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA