StackRadar

CVE-2024-48910

Critical

Advisory

Published 31 Oct 2024In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.012
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 1
affected package

DOMPurify vulnerable to tampering by prototype polution

Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
dompurifynpm2.1.1, 2.2.6, 2.2.7, 2.3.1+5 more2.4.217
OSV records
GHSA-p3vf-v8qc-cwcr

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
dompurify@2.4.1
2.4.2

Open the chart page →

4,431
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
dompurify@2.2.7
2.4.2

Open the chart page →

5,946
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
dompurify@2.4.1
2.4.2

Open the chart page →

10,530
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
dompurify@2.3.8
2.4.2

Open the chart page →

7,579
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
dompurify@2.3.10
2.4.2

Open the chart page →

10,311
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
dompurify@2.1.1
2.4.2

Open the chart page →

10,730
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
dompurify@2.3.4
2.4.2

Open the chart page →

7,801
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
dompurify@2.3.10
2.4.2

Open the chart page →

18,277
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
dompurify@2.1.1
2.4.2

Open the chart page →

5,806
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
dompurify@2.4.1
2.4.2

Open the chart page →

13,852
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
dompurify@2.2.6
2.4.2

Open the chart page →

4,043
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
dompurify@2.2.6
2.4.2

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
dompurify@2.2.6
2.4.2

Open the chart page →

24,319
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
dompurify@2.3.10
2.4.2

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
dompurify@2.3.10
2.4.2

Open the chart page →

2,682
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
dompurify@2.2.7
2.4.2

Open the chart page →

4,253
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
dompurify@2.3.10
2.4.2

Open the chart page →

2,685
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
dompurify@2.1.1
2.4.2

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
dompurify@2.1.1
2.4.2

Open the chart page →

10,603
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
dompurify@2.3.1
2.4.2

Open the chart page →

29,227
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
dompurify@2.4.1
2.4.2

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
dompurify@2.3.3
2.4.2

Open the chart page →

3,638
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2024-48910.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
dompurify@2.1.1
2.4.2

Open the chart page →

5,806

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
dompurify@2.3.10
2.4.2
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
dompurify@2.1.1
2.4.2
2
governify/assets-manager:v1.4.12987672448c7
dompurify@2.2.6
2.4.2
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
dompurify@2.1.1
2.4.2
2
outlinewiki/outline:0.69.1d060dcd8f9aa
dompurify@2.4.1
2.4.2
2
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
dompurify@2.1.1
2.4.2
1
assistiot/open_api_frontend:1.0.1f11d82defc70
dompurify@2.3.10
2.4.2
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
dompurify@2.3.8
2.4.2
1
kyso/kyso-front:lateste52595c5c16f
dompurify@2.3.10
2.4.2
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
dompurify@2.2.6
2.4.2
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
dompurify@2.4.1
2.4.2
1
requarks/wiki:canary-2.5.2438b5865a7386c
dompurify@2.2.7
2.4.2
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
dompurify@2.3.4
2.4.2
1
wazuh/wazuh-dashboard:4.4.11787550d2358
dompurify@2.4.1
2.4.2
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
dompurify@2.2.7
2.4.2
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
dompurify@2.3.1
2.4.2
1
quay.io/wekan/wekan:v5.65cb17600883a3
dompurify@2.3.3
2.4.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.