Shopify Hydrogen
cpe:2.3:a:shopify:hydrogen:*:*:*:*:node.js:*:*
- >= 0.10.0, <= 0.18.0
A Cross-Site Scripting (XSS) vulnerability has been identified in Shopify Hydrogen, a React-based framework for building custom storefronts. This issue allows arbitrary users to execute scripts on pages created with Hydrogen. The vulnerability affects all versions of Hydrogen from 0.10.0 to 0.18.0 and is exploitable in applications where the hydrating data is user-controlled.
Exploitation of this vulnerability allows for Cross-Site Scripting, where an attacker can inject and execute malicious scripts in the context of the user's browser.
Users are advised to upgrade to Shopify Hydrogen version 0.19.0. There is no effective workaround, and the Content Security Policy does not mitigate this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.