Description
Dark Reader versions prior to 4.9.117 included a behavior where a website could request a style sheet from a locally running web server, for example http://localhost:8080/style.css, If an address was available and returned a text/css content type.
Recommendation
Update the darkreader package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.9.117
- Patched version(s): 4.9.117
References
Could your website be exposed too?
SmartScanner can check your website for Dark Reader gives users the ability to request style sheets from local web servers and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module - CVE-2025-62505
- SillyTavern Web Interface Vulnerable DNS Rebinding - CVE-2025-59159
- TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update - CVE-2025-60542
- private-ip vulnerable to Server-Side Request Forgery - CVE-2025-8020


