docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access Token
- Severity:
- High
Description
No description available.
Recommendation
Update the docusaurus-plugin-content-gists package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.0.0
- Patched version(s): 4.0.0
References
Related Issues
- content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE - CVE-2025-55164
- @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Back - CVE-2025-25288
- Suspended Directus user can continue to use session token to access API - CVE-2025-30351
- Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler - CVE-2025-27098
You might also like:
- Tags:
- npm
- docusaurus-plugin-content-gists
Anything's wrong? Let us know Last updated on July 09, 2025


