Skip to content

Update dependency jquery to v3 [SECURITY]#9576

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-jquery-vulnerability
Open

Update dependency jquery to v3 [SECURITY]#9576
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-jquery-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 22, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
jquery (source) ~2.2.4~3.5.0 age adoption passing confidence

Potential XSS vulnerability in jQuery

CVE-2020-11023 / GHSA-jpcq-cgw6-v4j6

More information

Details

Impact

Passing HTML containing <option> elements from untrusted sources - even after sanitizing them - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.

Patches

This problem is patched in jQuery 3.5.0.

Workarounds

To workaround this issue without upgrading, use DOMPurify with its SAFE_FOR_JQUERY option to sanitize the HTML string before passing it to a jQuery method.

References

https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/

For more information

If you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N/E:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Cross-Site Scripting (XSS) in jquery

CVE-2015-9251 / GHSA-rmxg-73gg-4p98

More information

Details

Affected versions of jquery interpret text/javascript responses from cross-origin ajax requests, and automatically execute the contents in jQuery.globalEval, even when the ajax request doesn't contain the dataType option.

Recommendation

Update to version 3.0.0 or later.

Severity

  • CVSS Score: 6.1 / 10 (Medium)
  • Vector String: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


XSS in jQuery as used in Drupal, Backdrop CMS, and other products

CVE-2019-11358 / GHSA-6c3j-c64m-qhgq

More information

Details

jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Severity

  • CVSS Score: 6.1 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Note

PR body was truncated to here.

@renovate renovate Bot requested a review from a team as a code owner August 22, 2025 20:17
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from f3fb3e3 to e36f83e Compare August 31, 2025 11:54
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from e36f83e to 77ea814 Compare September 25, 2025 16:20
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 77ea814 to 481cf6a Compare October 21, 2025 18:16
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 481cf6a to 51e6dc7 Compare November 10, 2025 21:55
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 51e6dc7 to 586908f Compare November 18, 2025 15:05
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 586908f to 596986e Compare December 3, 2025 20:30
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 596986e to 9d931c7 Compare December 31, 2025 18:00
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 9d931c7 to 22e1465 Compare January 8, 2026 16:43
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch 2 times, most recently from 49d1536 to d9eeaa2 Compare January 21, 2026 15:02
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from d9eeaa2 to 3279cd0 Compare February 2, 2026 16:29
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch 2 times, most recently from 057f227 to 14bf11e Compare February 17, 2026 22:00
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 14bf11e to 162a3e2 Compare March 5, 2026 14:29
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 162a3e2 to 5720314 Compare March 13, 2026 12:44
@renovate renovate Bot changed the title Update dependency jquery to v3 [SECURITY] Update dependency jquery to v3 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot deleted the renovate/npm-jquery-vulnerability branch March 27, 2026 02:49
@renovate renovate Bot changed the title Update dependency jquery to v3 [SECURITY] - autoclosed Update dependency jquery to v3 [SECURITY] Mar 27, 2026
@renovate renovate Bot reopened this Mar 27, 2026
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch 3 times, most recently from f273609 to 8227316 Compare April 1, 2026 17:00
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch 2 times, most recently from 8030140 to ee3edb9 Compare April 13, 2026 03:54
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from ee3edb9 to 13bddf7 Compare April 17, 2026 15:03
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 13bddf7 to 97b78f4 Compare April 20, 2026 15:55
@renovate renovate Bot changed the title Update dependency jquery to v3 [SECURITY] Update dependency jquery to v3 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title Update dependency jquery to v3 [SECURITY] - autoclosed Update dependency jquery to v3 [SECURITY] Apr 28, 2026
@renovate renovate Bot reopened this Apr 28, 2026
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch 3 times, most recently from a7c9720 to 9344695 Compare April 29, 2026 09:42
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch 2 times, most recently from cf05491 to 734e79f Compare May 18, 2026 10:11
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch 2 times, most recently from 36ea1ea to e52c936 Compare June 1, 2026 14:46
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from e52c936 to 2dab582 Compare June 11, 2026 08:52
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 2dab582 to 5faa0f3 Compare June 12, 2026 14:12
@renovate renovate Bot force-pushed the renovate/npm-jquery-vulnerability branch from 5faa0f3 to 6a1c364 Compare June 18, 2026 18:08
@miq-bot

miq-bot commented Jun 18, 2026

Copy link
Copy Markdown
Member

Checked commit 6a1c364 with ruby 3.3.10, rubocop 1.86.0, haml-lint 0.73.0, and yamllint 1.37.1
0 files checked, 0 offenses detected
Everything looks fine. 🍰

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant