{"id":"GHSA-qhjf-hm5j-335w","summary":"@urql/next Cross-site Scripting vulnerability","details":"## impact\n\nThe `@urql/next` package is vulnerable to XSS. To exploit this an attacker would need to ensure that the response returns `html` tags and that the web-application is using streamed responses (non-RSC). This vulnerability is due to improper escaping of html-like characters in the response-stream.\n\nTo fix this vulnerability upgrade to version 1.1.1","aliases":["CVE-2024-24556"],"modified":"2026-09-10T03:50:09.382768474Z","published":"2024-01-30T20:57:28Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-01-30T20:57:28Z","nvd_published_at":"2024-01-30T18:15:48Z","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/urql-graphql/urql/security/advisories/GHSA-qhjf-hm5j-335w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24556"},{"type":"WEB","url":"https://github.com/urql-graphql/urql/commit/4b7011b70d5718728ff912d02a4dbdc7f703540d"},{"type":"PACKAGE","url":"https://github.com/urql-graphql/urql"}],"affected":[{"package":{"name":"@urql/next","ecosystem":"npm","purl":"pkg:npm/%40urql/next"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-qhjf-hm5j-335w/GHSA-qhjf-hm5j-335w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}