GHSA-33vc-wfww-vjfv

Suggest an improvement
Source
https://github.com/advisories/GHSA-33vc-wfww-vjfv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-33vc-wfww-vjfv/GHSA-33vc-wfww-vjfv.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-33vc-wfww-vjfv
Aliases
Downstream
Related
Published
2025-09-11T06:30:23Z
Modified
2025-09-12T21:57:19.248178Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P CVSS Calculator
Summary
jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin
Details

Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer using the built-in html formatter on a private website.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "severity": "LOW",
    "nvd_published_at": "2025-09-11T05:15:34Z",
    "github_reviewed_at": "2025-09-12T21:12:49Z"
}
References

Affected packages

npm / jsondiffpatch

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.2