VDB
Sign up
MEDIUM6.1

GHSA-ww7p-8gfg-v82r

Scrypted Cross-site Scripting vulnerability

Details

Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior (corresponding to `@scrypted/core` 0.1.142 and prior), a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can run arbitrary JavaScript code after the login. As of time of publication, no known patches are available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@scrypted/core
Introduced in: 0

No fixed version published yet for @scrypted/core (npm). Pin to a known-safe version or switch to an alternative.

References