{"api_version":"1","generated_at":"2026-07-23T14:03:31+00:00","cve":"CVE-2021-23342","urls":{"html":"https://cve.report/CVE-2021-23342","api":"https://cve.report/api/cve/CVE-2021-23342.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-23342","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-23342"},"summary":{"title":"CVE-2021-23342","description":"This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. 2) The isURL external check can be bypassed by inserting more “////” characters","state":"PUBLIC","assigner":"report@snyk.io","published_at":"2021-02-19 17:15:00","updated_at":"2021-02-25 22:22:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://github.com/docsifyjs/docsify/commit/ff2a66f12752471277fe81a64ad6c4b2c08111fe","name":"https://github.com/docsifyjs/docsify/commit/ff2a66f12752471277fe81a64ad6c4b2c08111fe","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"fix: isExternal check with malformed URL + tests (#1510) · docsifyjs/docsify@ff2a66f · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://snyk.io/vuln/SNYK-JS-DOCSIFY-1066017","name":"https://snyk.io/vuln/SNYK-JS-DOCSIFY-1066017","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Cross-site Scripting (XSS) in docsify | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076593","name":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076593","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Cross-site Scripting (XSS) in org.webjars.npm:docsify | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/161495/docsify-4.11.6-Cross-Site-Scripting.html","name":"http://packetstormsecurity.com/files/161495/docsify-4.11.6-Cross-Site-Scripting.html","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"docsify 4.11.6 Cross Site Scripting ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2021/Feb/71","name":"20210219 [KIS-2021-02] docsify <= 4.11.6 DOM-based Cross-Site Scripting Vulnerability","refsource":"FULLDISC","tags":["Mailing List","Third Party Advisory"],"title":"Full Disclosure: [KIS-2021-02] docsify <= 4.11.6 DOM-based Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-23342","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23342","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"GiuliCler (Giulia Clerici)","lang":""},{"source":"LEGACY","value":"Egidio Romano","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"23342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"docsifyjs","cpe5":"docsify","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"23342","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"docsifyjs","cpe5":"docsify","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-23342","qid":"982917","title":"Nodejs (npm) Security Update for docsify (GHSA-2mm9-c2fx-c7m4)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ASSIGNER":"report@snyk.io","DATE_PUBLIC":"2021-02-19T16:30:17.736948Z","ID":"CVE-2021-23342","STATE":"PUBLIC","TITLE":"Cross-site Scripting (XSS)"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"docsify","version":{"version_data":[{"version_affected":"<","version_value":"4.12.0"}]}}]},"vendor_name":"n/a"}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Cross-site Scripting (XSS)"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://snyk.io/vuln/SNYK-JS-DOCSIFY-1066017","name":"https://snyk.io/vuln/SNYK-JS-DOCSIFY-1066017"},{"refsource":"MISC","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076593","name":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1076593"},{"refsource":"MISC","url":"https://github.com/docsifyjs/docsify/commit/ff2a66f12752471277fe81a64ad6c4b2c08111fe","name":"https://github.com/docsifyjs/docsify/commit/ff2a66f12752471277fe81a64ad6c4b2c08111fe"},{"refsource":"FULLDISC","name":"20210219 [KIS-2021-02] docsify <= 4.11.6 DOM-based Cross-Site Scripting Vulnerability","url":"http://seclists.org/fulldisclosure/2021/Feb/71"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/161495/docsify-4.11.6-Cross-Site-Scripting.html","url":"http://packetstormsecurity.com/files/161495/docsify-4.11.6-Cross-Site-Scripting.html"}]},"description":{"description_data":[{"lang":"eng","value":"This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. 2) The isURL external check can be bypassed by inserting more “////” characters"}]},"impact":{"cvss":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:P/RL:U/RC:C","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"}},"credit":[{"lang":"eng","value":"GiuliCler (Giulia Clerici)"},{"lang":"eng","value":"Egidio Romano"}]},"nvd":{"publishedDate":"2021-02-19 17:15:00","lastModifiedDate":"2021-02-25 22:22:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:docsifyjs:docsify:*:*:*:*:*:*:*:*","versionEndExcluding":"4.12.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"23342","Ordinal":"198069","Title":"CVE-2021-23342","CVE":"CVE-2021-23342","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"23342","Ordinal":"1","NoteData":"This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. 2) The isURL external check can be bypassed by inserting more “////” characters","Type":"Description","Title":null},{"CveYear":"2021","CveId":"23342","Ordinal":"2","NoteData":"2021-02-19","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"23342","Ordinal":"3","NoteData":"2021-02-22","Type":"Other","Title":"Modified"}]}}}