MEDIUM
GHSA-9jmq-xgjm-p8c2
Sync-in Server has a stored cross-site scripting (XSS) vulnerability
Quick fix
GHSA-9jmq-xgjm-p8c2 — @sync-in/server: upgrade to the fixed version with the command below.
npm install @sync-in/server@1.9.3Details
A Stored Cross-Site Scripting (XSS) vulnerability in Sync-in Server before 1.9.3 allows an authenticated attacker to execute arbitrary JavaScript in a victim's browser. By uploading a crafted SVG file containing a malicious payload, an attacker can access and exfiltrate sensitive information, including the user's session cookies.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-67438[ADVISORY]
- https://github.com/Sync-in/server/commit/a6276d067725637310e4e83a3eee337aae81f439[WEB]
- https://gist.github.com/x0root/86db30af91bb0e1707eb7e57a049b6ad[WEB]
- https://github.com/Sync-in/server[PACKAGE]
- https://github.com/Sync-in/server/releases/tag/v1.9.3[WEB]