Versions of cyberchef prior to 8.31.3 are vulnerable to Cross-Site Scripting. In Text Encoding Brute Force the table rows are created by concatenating the value variable unsanitized in the HTML code. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser.
Upgrade to version 8.31.3 or later.
{
"cwe_ids": [
"CWE-79"
],
"nvd_published_at": null,
"github_reviewed": true,
"severity": "MODERATE",
"github_reviewed_at": "2019-08-27T15:50:14Z"
}