VDB
Sign up
MEDIUM4.3

GHSA-x9p2-fxq6-2m5f

Reverse Tabnapping in swagger-ui

Quick fix

GHSA-x9p2-fxq6-2m5f — swagger-ui: upgrade to the fixed version with the command below.

npm install swagger-ui@3.18.0

Details

Versions of `swagger-ui` prior to 3.18.0 are vulnerable to [Reverse Tabnapping](https://www.owasp.org/index.php/Reverse_Tabnabbing). The package uses `target='_blank'` in anchor tags, allowing attackers to access `window.opener` for the original page. This is commonly used for phishing attacks.

## Recommendation

Upgrade to version 3.18.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/swagger-ui
Introduced in: 0Fixed in: 3.18.0
Fixnpm install swagger-ui@3.18.0

References