MEDIUM4.3
GHSA-x9p2-fxq6-2m5f
Reverse Tabnapping in swagger-ui
Quick fix
GHSA-x9p2-fxq6-2m5f — swagger-ui: upgrade to the fixed version with the command below.
npm install swagger-ui@3.18.0Details
Versions of `swagger-ui` prior to 3.18.0 are vulnerable to [Reverse Tabnapping](https://www.owasp.org/index.php/Reverse_Tabnabbing). The package uses `target='_blank'` in anchor tags, allowing attackers to access `window.opener` for the original page. This is commonly used for phishing attacks.
## Recommendation
Upgrade to version 3.18.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/swagger-api/swagger-ui/pull/4789[WEB]
- https://github.com/swagger-api/swagger-ui/commit/3f4cae3334fdd492a373f4453bd03a9ebd87becf[WEB]
- https://github.com/swagger-api/swagger-ui/releases/tag/v3.18.0[WEB]
- https://snyk.io/vuln/SNYK-JS-SWAGGERUI-449808[WEB]
- https://www.npmjs.com/advisories/975[WEB]