CVE-2025-59332

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-59332
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-59332.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-59332
Aliases
  • GHSA-f2rp-232x-mqrh
Published
2025-09-15T20:15:39Z
Modified
2025-09-19T15:30:19.488936Z
Summary
[none]
Details

3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser function allow users to provide custom attributes that are then appended to the canvas HTML element that is being output by the extension. The attributes are not sanitized, which means that arbitrary JavaScript can be inserted and executed.

References

Affected packages

Git / github.com/dolfinus/3dalloy

Affected ranges

Type
GIT
Repo
https://github.com/dolfinus/3dalloy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8