QID 981664
QID 981664: Nodejs (npm) Security Update for cyberchef (GHSA-jp6r-xcjj-5h7r)
Versions of `cyberchef` prior to 8.31.3 are vulnerable to Cross-Site Scripting. In `Text Encoding Brute Force` the table rows are created by concatenating the `value` variable unsanitized in the HTML code. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser.
## Recommendation
Upgrade to version 8.31.3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jp6r-xcjj-5h7r for updates pertaining to this vulnerability.
Vendor References
- GHSA-jp6r-xcjj-5h7r -
github.com/advisories/GHSA-jp6r-xcjj-5h7r
CVEs related to QID 981664
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jp6r-xcjj-5h7r | cyberchef |
|