MEDIUM4.6
GHSA-q54r-r9pr-w7qv
Hexo Vulnerable to XSS
Quick fix
GHSA-q54r-r9pr-w7qv — hexo: upgrade to the fixed version with the command below.
npm install hexo@6.0.0Details
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-25987[ADVISORY]
- https://github.com/hexojs/hexo/issues/4838[WEB]
- https://github.com/hexojs/hexo/pull/4750[WEB]
- https://github.com/hexojs/hexo/commit/5170df2d3fa9c69e855c4b7c2b084ebfd92d5200[WEB]
- https://github.com/hexojs/hexo[PACKAGE]
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25987[WEB]