Update dependency rollup to v2.79.2 [SECURITY] - #396
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
September 28, 2024 04:32
a460183 to
6e854ef
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
2 times, most recently
from
August 13, 2025 15:37
68a17f5 to
14691dc
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
August 19, 2025 16:37
14691dc to
34662db
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
August 31, 2025 10:06
34662db to
cea35c5
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
September 25, 2025 21:37
cea35c5 to
bdbeddf
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
October 21, 2025 16:13
bdbeddf to
ca42215
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
November 10, 2025 15:15
ca42215 to
d2a5c39
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
November 18, 2025 12:59
d2a5c39 to
4a59d66
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
December 4, 2025 23:44
4a59d66 to
52e97e1
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
December 31, 2025 15:59
52e97e1 to
8ed6f39
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
January 8, 2026 19:27
8ed6f39 to
5ef7a6d
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
2 times, most recently
from
January 23, 2026 18:39
6aa79f4 to
e9706d1
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
February 2, 2026 21:15
e9706d1 to
c3d2c42
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
February 12, 2026 17:42
c3d2c42 to
2b50396
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
March 5, 2026 15:06
2b50396 to
1852275
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
March 13, 2026 15:48
1852275 to
fb0d7d2
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
March 30, 2026 21:05
fb0d7d2 to
1cf483c
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
April 8, 2026 17:20
1cf483c to
5555a92
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
3 times, most recently
from
April 29, 2026 17:57
ea57da2 to
b80b8bc
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
2 times, most recently
from
May 18, 2026 13:06
d61d03b to
198f335
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
2 times, most recently
from
June 1, 2026 18:47
0888b18 to
05592c1
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
June 11, 2026 19:56
05592c1 to
11f9c59
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
2 times, most recently
from
July 16, 2026 16:11
1bc9a47 to
be99695
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
2 times, most recently
from
July 24, 2026 20:00
3c2de12 to
422d504
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
July 30, 2026 17:47
422d504 to
4dd5d49
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
2 times, most recently
from
August 14, 2026 19:09
77a4755 to
5acd111
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
August 26, 2026 20:56
5acd111 to
1f35a4c
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
September 2, 2026 21:56
1f35a4c to
1132f7a
Compare
renovate
Bot
force-pushed
the
renovate/npm-rollup-vulnerability
branch
from
September 3, 2026 23:50
1132f7a to
f6bb369
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.79.1→2.79.2DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
CVE-2024-47068 / GHSA-gcx4-mw62-g8wm
More information
Details
Summary
We discovered a DOM Clobbering vulnerability in rollup when bundling scripts that use
import.meta.urlor with plugins that emit and reference asset files from code incjs/umd/iifeformat. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., animgtag with an unsanitizednameattribute) are present.It's worth noting that we’ve identifed similar issues in other popular bundlers like Webpack (CVE-2024-43788), which might serve as a good reference.
Details
Backgrounds
DOM Clobbering is a type of code-reuse attack where the attacker first embeds a piece of non-script, seemingly benign HTML markups in the webpage (e.g. through a post or comment) and leverages the gadgets (pieces of js code) living in the existing javascript code to transform it into executable code. More for information about DOM Clobbering, here are some references:
[1] https://scnps.co/papers/sp23_domclob.pdf
[2] https://research.securitum.com/xss-in-amp4email-dom-clobbering/
Gadget found in
rollupWe have identified a DOM Clobbering vulnerability in
rollupbundled scripts, particularly when the scripts usesimport.metaand set output in format ofcjs/umd/iife. In such cases,rollupreplaces meta property with the URL retrieved fromdocument.currentScript.https://github.com/rollup/rollup/blob/b86ffd776cfa906573d36c3f019316d02445d9ef/src/ast/nodes/MetaProperty.ts#L157-L162
https://github.com/rollup/rollup/blob/b86ffd776cfa906573d36c3f019316d02445d9ef/src/ast/nodes/MetaProperty.ts#L180-L185
However, this implementation is vulnerable to a DOM Clobbering attack. The
document.currentScriptlookup can be shadowed by an attacker via the browser's named DOM tree element access mechanism. This manipulation allows an attacker to replace the intended script element with a malicious HTML element. When this happens, thesrcattribute of the attacker-controlled element (e.g., animgtag ) is used as the URL for importing scripts, potentially leading to the dynamic loading of scripts from an attacker-controlled server.PoC
Considering a website that contains the following
main.jsscript, the devloper decides to use therollupto bundle up the program:rollup main.js --format cjs --file bundle.js.The output
bundle.jsis shown in the following code snippet.Adding the
rollupbundled script,bundle.js, as part of the web page source code, the page could load theextra.jsfile from the attacker's domain,attacker.controlled.serverdue to the introduced gadget during bundling. The attacker only needs to insert animgtag with the name attribute set tocurrentScript. This can be done through a website's feature that allows users to embed certain script-less HTML (e.g., markdown renderers, web email clients, forums) or via an HTML injection vulnerability in third-party JavaScript loaded on the page.Impact
This vulnerability can result in cross-site scripting (XSS) attacks on websites that include rollup-bundled files (configured with an output format of
cjs,iife, orumdand useimport.meta) and allow users to inject certain scriptless HTML tags without properly sanitizing thenameoridattributes.Patch
Patching the following two functions with type checking would be effective mitigations against DOM Clobbering attack.
Severity
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
rollup/rollup (rollup)
v2.79.2Compare Source
2024-09-26
Bug Fixes
Pull Requests
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.