VYPR

npm package

dom-expressions

pkg:npm/dom-expressions

Vulnerabilities (1)

  • CVE-2025-27108HigFeb 21, 2025
    affected < 0.39.5fixed 0.39.5

    dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering. In affected versions the use of javascript's `.replace()` opens up to potential Cross-site Scripting (XSS) vulnerabilities with the special replacement patterns beginning with `$`. Particularly, when the attr