RSSHub Cross-site Scripting vulnerability caused by internal media proxy
- Severity:
- Medium
Description
When the specially crafted image is supplied to the internal media proxy, it proxies the image without handling XSS vulnerabilities, allowing for the execution of arbitrary JavaScript code.
Users who access the deliberately constructed URL are affected.
Recommendation
Update the rsshub package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.0.0-master.cbbd829, < 1.0.0-master.d8ca915
- Patched version(s): 1.0.0-master.d8ca915
References
Related Issues
- CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection - CVE-2024-24815
- Cross-site scripting vulnerability in TinyMCE - tinymce - CVE-2024-21911
- Cross-site scripting vulnerability in TinyMCE plugins - CVE-2024-21910
- Cross-site scripting vulnerability in TinyMCE - CVE-2024-21908
You might also like:
- Tags:
- npm
- rsshub
Anything's wrong? Let us know Last updated on March 21, 2024


