
I found a stored XSS vulnerability in @LenisSmooth that affected 800,000+ weekly npm downloads across Next.js, Nuxt, and SvelteKit deployments. Fixed in v1.3.22. Assigned CVE-2026-41251. If you're using Lenis — please update now. #BugBounty #XSS #WebSecurity #OpenSource #CVE https://t.co/tsfYQ33N3I
Post summary
A stored XSS vulnerability was discovered in LenisSmooth that affected over 800k weekly npm downloads; the issue has been fixed in v1.3.22 and users are advised to update.
