Tag cve-2025-11842

Vulnerability identified in Smidge CVE-2025-11842

smidge-define-bundle

Smidge – A lightweight library for runtime CSS and JavaScript file management, minification, combination & compression in Microsoft .NET. In Program.cs of a .NET web application a Smidge Javascript bundle is defined with “CreateJs”. This module is vulnerable to arbitrary…