QID 982581
QID 982581: Nodejs (npm) Security Update for docsify (GHSA-qpqh-46qj-vwcw)
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qpqh-46qj-vwcw for updates pertaining to this vulnerability.
Vendor References
- GHSA-qpqh-46qj-vwcw -
github.com/advisories/GHSA-qpqh-46qj-vwcw
CVEs related to QID 982581
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qpqh-46qj-vwcw | docsify |
|