CVE-2024-45389 affects Pagefind, a static search library, prior to version 1.1.1. The vulnerability, a medium-severity CWE-79 (Improper Neutralization of Input During Web Page Generation), allows an attacker to manipulate how Pagefind loads its dependencies by injecting benign HTML that clobbers the document.currentScript.src lookup. This could lead to Pagefind loading resources from an external, attacker-controlled domain, escalating privileges if the attacker already has limited HTML injection capabilities. While the CVSS score is 5.4 (Medium) due to user interaction and low impact on confidentiality and integrity, there are no known exploits in the wild, no public exploit code, and minimal community discussion, indicating low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.1CPE matchmatch criteria | cpe:2.3:a:pagefind:pagefind:*:*:*:*:*:*:*:* | ||
1.1.1CPE matchmatch criteria | cpe:2.3:a:pagefind:pagefind:1.1.1:alpha0:*:*:*:*:*:* | ||
1.1.1CPE matchmatch criteria | cpe:2.3:a:pagefind:pagefind:1.1.1:alpha1:*:*:*:*:*:* | ||
1.1.1CPE matchmatch criteria | cpe:2.3:a:pagefind:pagefind:1.1.1:alpha2:*:*:*:*:*:* | ||
1.1.1CPE matchmatch criteria | cpe:2.3:a:pagefind:pagefind:1.1.1:alpha3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.