Skip to content

Conversation

aikido-autofix[bot]
Copy link
Contributor

This PR will resolve the following CVEs:

CVE ID Severity Description
AIKIDO-2025-10318
LOW
Affected versions of this package do not support the TrustedTypes API, which is designed to prevent DOM-based injection attacks such as Cross-Site Scripting (XSS). When used in environments enforcing TrustedTypes, Swiper.js fails to wrap dynamic HTML assignments with innerHTML. An attacker could...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants