Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
https://github.com/scullyio/scully/pull/1182
Related Vulnerabilities
CVE-2020-13410 Vulnerability in npm package aedes
CVE-2016-10604 Vulnerability in npm package dalek-browser-chrome
CVE-2023-23936 Vulnerability in npm package undici
CVE-2022-25901 Vulnerability in npm package cookiejar
CVE-2023-33246 Vulnerability in maven package org.apache.rocketmq:rocketmq-namesrv