Vue. Potential XSS In SSR When Using v-bind On Versions Under 2.5.17

< 1 min read

Impact area

Security

Severity

Medium

Affected element

ServiceNow

UI Script

Salesforce

Static Resource

Rule number

SN-JSL-VUE-LESSTHAN-V2517 (for ServiceNow)

SF-JSL-VUE-LESSTHAN-V2517 (for Salesforce)

Impact #

 Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when spread attributes in the ssr files are unsanitized and can therefore be attack vectors for untrusted user input.

Remediation

Update vue JS library to the latest version.

Time to fix

30 min

References #

This rule is linked to Common Weakness Enumeration CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’).

Updated on March 21, 2025
Table of contents
Was it helpful ?