WhisperX tag archive

#dom-clobbering

This page collects WhisperX intelligence signals tagged #dom-clobbering. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-01 11:27:18 · GitHub Issues

1. GitHub Security Patch: Markdown Preview Vulnerabilities Exposed to DOM Clobbering Attacks

GitHub has urgently patched a series of HTML filter bypasses in its Markdown preview feature, a vulnerability that could have allowed attackers to execute arbitrary scripts. The flaw, a reflected script injection for normal users and a stored one for staff, was exploitable through a technique known as DOM clobbering. A...

The Lab · 2026-05-12 13:48:30 · GitHub Issues

2. Vite Build Tool Patches Critical DOM Clobbering Flaw Enabling XSS Attacks

The Vite development build tool has released version 6.0.0, addressing a critical DOM Clobbering vulnerability that could allow cross-site scripting (XSS) attacks through specially crafted scripts in Vite-bundled output. The security flaw, tracked as CVE-2024-45812 and documented in GitHub Advisory GHSA-64vr-g452-qvp3,...

The Lab · 2026-05-12 15:48:24 · GitHub Issues

3. Webpack AutoPublicPathRuntimeModule DOM Clobbering Vulnerability Exposes Applications to XSS — CVE-2024-43788

A critical DOM Clobbering vulnerability has been identified in Webpack's `AutoPublicPathRuntimeModule`, potentially enabling Cross-Site Scripting (XSS) attacks in applications that rely on affected versions of the bundler. The flaw, tracked as CVE-2024-43788 and catalogued under GHSA-4vvj-4cpr-p986, affects webpack ver...