Vulnerabilities/

CyberChef has a Cross-site Scripting issue

Severity:
High

Description

GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets(‘%3Cscript substring.

Recommendation

Update the cyberchef package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
cyberchef
Anything's wrong? Let us know Last updated on May 06, 2026