{"id":"CVE-2024-24556","aliases":["GHSA-qhjf-hm5j-335w"],"url":"https://o3.security/vulnerability/CVE-2024-24556","summary":"XSS in @urql/next","details":"urql is a GraphQL client that exposes a set of helpers for several frameworks.  The `@urql/next` package is vulnerable to XSS. To exploit this an attacker would need to ensure that the response returns `html` tags and that the web-application is using streamed responses (non-RSC). This vulnerability is due to improper escaping of html-like characters in the response-stream. To fix this vulnerability upgrade to version 1.1.1","published":"2024-01-30T17:21:19.964Z","modified":"2026-08-12T03:51:21.646333539Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":{"score":0.00355,"percentile":0.28779,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@urql/next","fixedVersion":"1.1.1"}],"fix":{"url":"https://github.com/urql-graphql/urql/commit/4b7011b70d5718728ff912d02a4dbdc7f703540d","label":"urql-graphql/urql@4b7011b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24556.json"},{"type":"ADVISORY","url":"https://github.com/urql-graphql/urql/security/advisories/GHSA-qhjf-hm5j-335w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24556"},{"type":"FIX","url":"https://github.com/urql-graphql/urql/commit/4b7011b70d5718728ff912d02a4dbdc7f703540d"},{"type":"PACKAGE","url":"https://github.com/urql-graphql/urql"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.646333539Z"}}