Description
Versions of cyberchef prior to 8.31.3 are vulnerable to Cross-Site Scripting. In Text Encoding Brute Force the table rows are created by concatenating the value variable unsanitized in the HTML code. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim’s browser.
Recommendation
Update the cyberchef package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.31.3
- Patched version(s): 8.31.3
References
Related Issues
- Cross-Site Scripting in serialize-to-js - CVE-2019-16772
- Cross-site Scripting in pandao editor.md - CVE-2019-14517
- Cross-site Scripting in node-red-dashboard - CVE-2019-10756
- Cross-site Scripting in pandao - CVE-2019-14653
You might also like:
- Tags:
- npm
- cyberchef
Anything's wrong? Let us know Last updated on January 09, 2023


