CVE-2024-9440: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation. Software that depends on this library to dynamically generate lists using unsanitized user-provided input may be vulnerable to cross-site scripting, resulting in attacker executed JavaScript. At this time, no patch is available.
AI Analysis
Technical Summary
CVE-2024-9440 affects Slim Select versions 2.0 through 2.9.0. The vulnerability arises in the select.ts file within the createOption() function, where the text property from a user-provided Options object is assigned directly to innerHTML without proper sanitization. This improper neutralization of input can lead to cross-site scripting (CWE-79), enabling attackers to execute arbitrary JavaScript in the context of the affected application. No official fix or patch is currently available for this issue.
Potential Impact
Exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the affected web application, potentially leading to information disclosure or manipulation of the user interface. The CVSS score of 5.4 reflects a medium severity with low complexity and no required privileges but requires user interaction. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
At present, no patch or official fix is available for this vulnerability. Users of Slim Select should avoid using untrusted or unsanitized input in the Options object passed to createOption(). Implementing manual input sanitization or escaping before passing data to Slim Select may reduce risk until an official fix is released. Monitor the vendor or project repository for updates regarding a patch.
CVE-2024-9440: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Description
Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation. Software that depends on this library to dynamically generate lists using unsanitized user-provided input may be vulnerable to cross-site scripting, resulting in attacker executed JavaScript. At this time, no patch is available.
CVSS v3.1
Score 5.4medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-9440 affects Slim Select versions 2.0 through 2.9.0. The vulnerability arises in the select.ts file within the createOption() function, where the text property from a user-provided Options object is assigned directly to innerHTML without proper sanitization. This improper neutralization of input can lead to cross-site scripting (CWE-79), enabling attackers to execute arbitrary JavaScript in the context of the affected application. No official fix or patch is currently available for this issue.
Potential Impact
Exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the affected web application, potentially leading to information disclosure or manipulation of the user interface. The CVSS score of 5.4 reflects a medium severity with low complexity and no required privileges but requires user interaction. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
At present, no patch or official fix is available for this vulnerability. Users of Slim Select should avoid using untrusted or unsanitized input in the Options object passed to createOption(). Implementing manual input sanitization or escaping before passing data to Slim Select may reduce risk until an official fix is released. Monitor the vendor or project repository for updates regarding a patch.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2024-10-02T17:45:54.918Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 692a5c732a13ea799fd8c86b
Added to database: 11/29/2025, 02:37:39 UTC
Last enriched: 07/15/2026, 09:48:44 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 275
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.