VDB
Sign up
MEDIUM6.1

GHSA-32gr-4cq6-5w5q

rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters

Quick fix

GHSA-32gr-4cq6-5w5q — rsshub: upgrade to the fixed version with the command below.

npm install rsshub@1.0.0-master.c910c4d

Details

### Impact

When the URL parameters contain certain special characters, it returns an error page that does not properly handle XSS vulnerabilities, allowing for the execution of arbitrary JavaScript code.

Users who access the deliberately constructed URL are affected.

### Patches

This vulnerability was fixed in version c910c4d28717fb860fbe064736641f379fab2c91. Please upgrade to this or a later version.

### Workarounds

No.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/rsshub
Introduced in: 0Fixed in: 1.0.0-master.c910c4d
Fixnpm install rsshub@1.0.0-master.c910c4d

References