CVE-2020-26239

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-26239
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-26239.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-26239
Related
  • GHSA-6qfq-px3r-xj4p
Published
2020-11-23T19:15:11.117Z
Modified
2025-11-14T11:01:24.636860Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Scratch Addons is a WebExtension that supports both Chrome and Firefox. Scratch Addons before version 1.3.2 is vulnerable to DOM-based XSS. If the victim visited a specific website, the More Links addon of the Scratch Addons extension used incorrect regular expression which caused the HTML-escaped values to be unescaped, leading to XSS. Scratch Addons version 1.3.2 fixes the bug. The extension will be automatically updated by the browser. More Links addon can be disabled via the option of the extension.

References

Affected packages

Git / github.com/scratchaddons/scratchaddons

Affected ranges

Type
GIT
Repo
https://github.com/scratchaddons/scratchaddons
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v1.*

v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1