There is 1 open security issue in trixie.
1 issue left for the package maintainer to handle:
- CVE-2024-53382:
(needs triaging)
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
You can find information about how to handle this issue in the security team's documentation.