Description
On HTML elements handled by Orejime, one could run malicious code by embedding javascript: code within data attributes. When consenting to the related purpose, Orejime would turn data attributes into unprefixed ones (i.e. data-href into href), thus executing the code.
Recommendation
Update the orejime package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.3.2
- Patched version(s): 2.3.2
References
Could your website be exposed too?
SmartScanner can check your website for Orejime has executable code in HTML attributes and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups - @babel/helpers - CVE-2025-27789
- Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering - CVE-2025-54075
- Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups - @babel/runtime - CVE-2025-27789
- Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups - CVE-2025-27789


