OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer
- Severity:
- Medium
Description
XSS via .py
file containing script tag interpreted as HTML
Recommendation
Update the @openlist-frontend/openlist-frontend
package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.0.0-rc.3
- Patched version(s): 4.0.0-rc.4
References
Related Issues
- HackMD MCP Server has Server-Side Request Forgery (SSRF) vulnerability - CVE-2025-59155
- Potential DoS when using ContextLines integration (GHSA-r5w7-f542-q2j4) - Vulnerability
- Predictable results in nanoid generation when given non-integer values - CVE-2024-55565
- happy-dom allows for server side code to be executed by a <script> tag - CVE-2024-51757
- Tags:
- npm
- @openlist-frontend/openlist-frontend
Anything's wrong? Let us know Last updated on June 19, 2025