CVE-2025-59332

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-59332
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-59332.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-59332
Aliases
  • GHSA-f2rp-232x-mqrh
Published
2025-09-15T20:06:56.961Z
Modified
2025-12-02T20:15:27.206978Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L CVSS Calculator
Summary
3DAlloy allows stored XSS through attributes provided to the 3d parser tag/function
Details

3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser function allow users to provide custom attributes that are then appended to the canvas HTML element that is being output by the extension. The attributes are not sanitized, which means that arbitrary JavaScript can be inserted and executed.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59332.json"
}
References

Affected packages

Git / github.com/dolfinus/3dalloy

Affected ranges

Type
GIT
Repo
https://github.com/dolfinus/3dalloy
Events

Affected versions

1.*

1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8